Hi C4G/BLIS maintainers,
I'm a security researcher and I've found a security issue in BLIS that I'd like to report privately
(I'm not including any details here for obvious reasons — BLIS handles patient/lab data).
Could you either:
- enable GitHub's Private vulnerability reporting (repo Settings → Code security and analysis →
"Private vulnerability reporting" → Enable), which gives us a private thread and lets you publish
an advisory / request a CVE afterwards; or
- share a security contact (email) I can send the full write-up and PoC to?
I'll follow coordinated disclosure — nothing public until there is a fix. Thanks!
Hi C4G/BLIS maintainers,
I'm a security researcher and I've found a security issue in BLIS that I'd like to report privately
(I'm not including any details here for obvious reasons — BLIS handles patient/lab data).
Could you either:
"Private vulnerability reporting" → Enable), which gives us a private thread and lets you publish
an advisory / request a CVE afterwards; or
I'll follow coordinated disclosure — nothing public until there is a fix. Thanks!