The problem
A public issue tracker is the wrong place for a vulnerability: it publishes the reporter and the defect before anyone can look at either.
The design choice
The security route states where private reporting goes and where its boundary is, and that statement is bound to a published evidence id rather than to a promise.
The constraint
This site is static-first: it holds no intake service of its own, so the reporting path has to leave the site and say so plainly.
How it is implemented
The published claim is bound to the private-reporting advisory destination and to the security route itself, so a reader can follow both and check the statement.
Limitations
No bug bounty, no response time commitment and no certification are claimed. This site does not itself receive reports — it states the private channel and its boundary.
Security
Report privately, responsibly
Report security issues through a private channel. Do not open a public GitHub issue for vulnerability reports.
Opens GitHub private vulnerability reporting — visible only to maintainers
No bug-bounty, SLA, or certification badges are published without verified evidence.
Bilingual evidence mirror
The localized route remains the primary reading path; these authored pairs let you compare the exact wording.
Private vulnerability reporting is available through GitHub security advisories, visible only to maintainers.
Kênh báo cáo lỗ hổng riêng tư khả dụng qua GitHub security advisories, chỉ người bảo trì nhìn thấy.
Reporting does not establish a bug-bounty program, a response-time SLA, or a right to public disclosure.
Việc báo cáo không xác lập chương trình bug-bounty, cam kết thời gian phản hồi, hay quyền công bố công khai.
Verify this page
Source-linked means every claim on this page cites at least one public source you can open.
Vulnerability reports reach the maintainers through GitHub private advisories, and the security route publishes no unproven badges.
See the evidence
Reviewed: — content review
It does not establish a bug-bounty program, a response-time SLA, or a right to public disclosure.
Source to surface
- ClaimSecurity reports reach the maintainers through a private GitHub channel, never through a public issue.
- EvidenceGitHub private vulnerability reporting
- EvidenceSecurity reporting route
- BoundaryPrivate vulnerability reporting is available through GitHub security advisories, visible only to maintainers.
- SurfaceSecurity surface