Request to Enable Private Vulnerability Reporting on GitHub

Sanghyun Park via busybox <[email protected]> Wed, 27 May 2026 17:25:12 +0900
Newsgroups gmane.linux.busybox
Message-ID <CAOrxSK5GdD7uGU=zfKzafx-apb6emrqv5kMLJfOqmgqH9Sk6uw@mail.gmail.com>
--===============9199010215416631652==
Content-Type: multipart/alternative; boundary="000000000000e0ae580652c85b3c"

--000000000000e0ae580652c85b3c
Content-Type: text/plain; charset="UTF-8"

Hello BusyBox,

Thank you for all your hard work maintaining BusyBox.

I wanted to kindly follow up on the GitHub issue I opened several weeks ago:

"Please enable GitHub Private Vulnerability Reporting #4"
(https://github.com/vda-linux/busybox_mirror/issues/4)

Since BusyBox vulnerability reporting appears to have moved from
bugs.busybox.net to GitHub, would it be possible to *enable GitHub Private
Vulnerability Reporting* for the repository?

This would allow researchers to report vulnerabilities *privately* through
GitHub instead of using public Issues.

It should only require enabling:

Settings -> Security and quality -> Advanced Security -> Private
vulnerability reporting

Thank you for considering this.

Best regards,
Sanghyun Park

--000000000000e0ae580652c85b3c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello BusyBox,<br><br>Thank you for all your hard work mai=
ntaining BusyBox.<br><br>I wanted to kindly follow up on the GitHub issue I=
 opened several weeks ago:<br><br>&quot;Please enable GitHub Private Vulner=
ability Reporting #4&quot;<div>(<a href=3D"https://github.com/vda-linux/bus=
ybox_mirror/issues/4" target=3D"_blank">https://github.com/vda-linux/busybo=
x_mirror/issues/4</a>)<br><br>Since BusyBox vulnerability reporting appears=
 to have moved from=C2=A0<a href=3D"http://bugs.busybox.net/" target=3D"_bl=
ank">bugs.busybox.net</a>=C2=A0to GitHub, would it be possible to=C2=A0<b>e=
nable GitHub Private Vulnerability Reporting</b>=C2=A0for the repository?<b=
r><br>This would allow researchers to report vulnerabilities=C2=A0<b>privat=
ely</b>=C2=A0through GitHub instead of using public Issues.<br><br>It shoul=
d only require enabling:<br><br>Settings -&gt; Security and quality -&gt; A=
dvanced Security -&gt; Private vulnerability reporting<br><br>Thank you for=
 considering this.<br><br>Best regards,<br>Sanghyun Park</div></div>

--000000000000e0ae580652c85b3c--

--===============9199010215416631652==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
busybox mailing list
[email protected]
https://lists.busybox.net/mailman/listinfo/busybox

--===============9199010215416631652==--