No SECURITY.md and no working disclosure channel — #1622 has asked 'where do I report a vulnerability?' since March, unanswered
Hi, and thank you for Eureka.
The gap: this repository has no SECURITY.md (checked the repo and the Netflix/.github org defaults), so GitHub shows no security policy — and it has a real cost: #1622, "Where can I report a security vulnerability?", has been open since March 27 with zero replies. Someone claims to be holding a vulnerability report right now with nowhere to send it.
Why I'm not sending a PR instead: the obvious template is metaflow's SECURITY.md, which routes reports to https://bugcrowd.com/netflix — but I checked before writing this, and that page returns 404 today (bugcrowd.com itself is up, so it's not a bot-block; the program page appears to be gone). Which channel is currently correct — a Bugcrowd program under a new URL, an email alias, GitHub private vulnerability reporting — is an attestation only Netflix can make, so a guess-based PR from outside would be worse than the gap.
Suggested resolution (whichever channel is right):
- add a ~10-line
SECURITY.mdnaming the current channel (happy to send that PR the moment you name it); - and/or enable GitHub's private vulnerability reporting on this repo, which gives reporters a button with no docs required;
- and a one-line reply on #1622 so the waiting reporter isn't stranded.
For transparency: I used AI assistance in preparing this; I verified the missing files, the state of #1622, and the 404 myself today.
Source: Netflix/eureka