Skip to content

[Bug]: Private channel for reporting a security issue #4221

@Wang-Haimin

Description

@Wang-Haimin

Mapbox Version

N/A

React Native Version

N/A

Platform

Android

@rnmapbox/maps version

N/A

Standalone component to reproduce

Hello maintainers,

I found a potential security issue affecting GitHub Actions workflows in this repository.

I do not want to disclose technical details publicly before maintainers have reviewed them. Could you please enable GitHub private vulnerability reporting or provide an alternative private security contact email?

I can provide a detailed report including:

  • affected workflow paths;
  • current affected commit;
  • vulnerability mechanism;
  • required attacker permissions and preconditions;
  • security impact assessment;
  • non-destructive validation steps;
  • suggested remediation.

Thank you.

Observed behavior and steps to reproduce

No response

Expected behavior

No response

Notes / preliminary analysis

No response

Additional links and references

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions