#1522·kirara-ai

Security: could you enable a private channel so I can report a workflow issue? / 能否开启私密渠道以便报告一个 workflow 安全问题?

作者: kobihikri创建于 2026年7月29日更新于 2026年7月29日

Hello, and thank you for Kirara AI. I think I have found a security issue in one of the repository's GitHub Actions workflows, and I would like to report it **privately** rather than describe it in a public issue — a public description would effectively be a disclosure before you have had a chance to act. I could not find a private channel for the project: there is no `SECURITY.md`, and GitHub's private vulnerability reporting does not appear to be enabled. Could you either: - enable **private vulnerability reporting** (Settings → Security → *Private vulnerability reporting*), or - add a `SECURITY.md` with a contact, or - share a security contact (email / other) here, so I can send the details privately? Once a channel exists I will send the full write-up, which includes the affected file, the exact lines, and a suggested fix. It is a workflow-configuration issue rather than anything in the deployed bot, and I have not run anything against your infrastructure. Thank you for your time.

内容来源: lss233/kirara-ai