Skip to content

Security: request a private disclosure channel for openapi-generator-online finding #24375

Description

@iabdullah215

Hi maintainers,

I've identified a security issue in the openapi-generator-online component
and would like to report it responsibly.

I previously emailed team@openapitools.org about this on 11th July
but haven't received a reply, so I'm following up here to find the right
channel.

The repository does not currently have a SECURITY.md, and private
vulnerability reporting does not appear to be enabled under the Security tab,
so I don't have a private channel to send the details.

Could a maintainer either:

  1. Enable GitHub private vulnerability reporting for this repo
    (Settings → Security → "Private vulnerability reporting"), or
  2. Share a private contact I can send the full report to

I'm intentionally not including any technical details here to avoid public
disclosure before a fix. I have a working proof-of-concept and a suggested
fix ready to share privately.

Thanks — happy to follow whatever process you prefer.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions