Request: a private channel for reporting a security issue (no details here)

Author: coggiyadminCreated Aug 26, 2026Updated Aug 28, 2026

Hi — I'd like to report a security issue in this project privately, but I can't find a channel for it.

There's no SECURITY.md in the repo, and GitHub's private vulnerability reporting is not enabled, so the only route available to me is a public issue — which would mean publicly disclosing an unpatched flaw before you've had a chance to look at it. I'd rather not do that.

Deliberately no details here. This issue is only a request for a channel.

Could you either:

  1. Enable private vulnerability reporting (repo → Settings → Security → Private vulnerability reporting), which gives us a private thread on GitHub with no email involved; or
  2. Add a SECURITY.md with a security contact address; or
  3. Reply here with an address I can use.

For context on what to expect: the finding came out of a static-analysis benchmark run over public repositories. I reproduced it locally from a fresh clone — nothing was tested against any hosted instance — and I have a written report ready to send, including affected file and line, impact, a local reproduction, and a suggested fix.

I'm not asking for a bounty and there's no deadline attached from my side. Happy to follow whatever disclosure timeline you prefer once there's somewhere private to send it.

Thanks.