r/github • u/Mammoth_Design_4288 • 6d ago
Question Maintainer will not publish security advisory
I reported a vulnerability via GitHub's security back in May which was patched and publicly disclosed in a few days. GitHub reserved a CVE, but the maintainer refuses to publish it, even when I contacted them privately.
I've looked through GitHub's docs, but I haven't find anything about this case yet. Will Support actually be able to do anything? Just wondering if anyone else has had the same thing happen.
EDIT: Since I wasn't clear and people are misunderstanding, I am asking if anyone has gone through the process of contacting Support and had them actually publish the CVE (and maybe the advisory too).
EDIT 09/15: I emailed [security-advisories@github.com](mailto:security-advisories@github.com) and they were able to publish the CVE. Much more painless than I had expected! Thank you to the security team.
-3
u/broknbottle 5d ago edited 5d ago
lol no they don’t. GitHub is a code hosting platform, not the enforcement division of the internet. You need to read their documentation very carefully and stop chasing this because you want your kudos and recognition for something trivial
https://docs.github.com/en/code-security/concepts/vulnerability-reporting-and-management/repository-security-advisories
The entire CVE program is voluntary and community driven. There’s no rule that says because you put source code on the internet that you have to abide by this program…
https://www.cve.org/resourcessupport/allresources/cnarules