We currently do not support GitHub Private Vulnerability Reporting for ASF projects.

This might be interesting in the future, but currently missing are:

  • Often, the PMC will want to have a private discussion about a report before confirming/rejecting it to the reporter. Currently the GitHub Private Vulnerability Reporting feature does not have a mechanism for this, and spreading this over the report and the PMC mailinglist is awkward. We have shared this feature request with our contacts at GitHub.
  • We need a way to make each report available to all PMC members. This is something Infra can likely implement, but is not currently available.
  • We need a record of all communication on the private reports on ASF infrastructure. This is something Infra can likely implement, but is not currently available.
  • No labels