Hi — I've been reviewing FreeToken and have a couple of security findings I'd like to report privately
and coordinate a fix/disclosure on. I don't want to post details in a public issue.
I noticed the repo doesn't currently have a private disclosure channel:
- no
SECURITY.md / security policy, and
- GitHub Private Vulnerability Reporting does not appear to be enabled (Security → Advisories has no "Report a vulnerability" option).
Could you please set up one of the following so I can send the full write-up privately?
- Enable Private Vulnerability Reporting — repo Settings → Security → Private vulnerability reporting → Enable. That gives us a private GitHub advisory thread (and a smooth path to a GHSA/CVE if warranted). (preferred)
- Or add a
SECURITY.md with a security contact (email is fine).
- Or just reply here / to my profile with an email address to use.
Happy to follow whatever coordinated-disclosure timeline you prefer once a channel is up. Thanks!
Hi — I've been reviewing FreeToken and have a couple of security findings I'd like to report privately
and coordinate a fix/disclosure on. I don't want to post details in a public issue.
I noticed the repo doesn't currently have a private disclosure channel:
SECURITY.md/ security policy, andCould you please set up one of the following so I can send the full write-up privately?
SECURITY.mdwith a security contact (email is fine).Happy to follow whatever coordinated-disclosure timeline you prefer once a channel is up. Thanks!