#1122·pinokio

Security: please enable private vulnerability reporting

Author: zer0d4y5Created Sep 10, 2026Updated Sep 10, 2026

Hi — I'm a security researcher and I have a security vulnerability to report in Pinokio (the desktop app). I don't want to disclose details in a public issue.

The repo has no SECURITY.md and GitHub's Private Vulnerability Reporting is currently disabled, so there's no private channel to use. Could you either:

  1. Enable Private Vulnerability Reporting (Settings → Advanced Security → Private vulnerability reporting), which lets me file the report privately as a draft advisory, or
  2. Point me at a security contact / email?

Happy to share full details and a proof-of-concept as soon as a private channel exists. Thanks!