Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And also an exception for reporting security-related issues. Because if you try and charge people money to responsibly report security vulnerabilities, then they'll just end up taking the full disclosure approach, which is probably not what you want.


Oh, definitely. CVEs have a special place to be reported in GitHub.

PSA: Do NOT use the issue tracker to report a CVE. That makes everyone's life difficult. Go through the correct channel.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: