On Mon, 5 Oct 2026 at 17:05, Aditya <[email protected]> wrote:
> Hi Team, > > I'm an independent cybersecurity professional and recently came across a > security concern affecting one of your external systems. > > Could you let me know the appropriate channel for responsible disclosure? > > A security contact email, bug bounty page, or disclosure policy would be > most helpful. > > Thanks, > Aditya > Cybersecurity Researcher > 1. If it's related to github actions, email [email protected] and they will act faster; to take things off line. 2. the ASF doesn't have a bug bounty scheme, though some organisations which route reports to the ASF do 3. all open source projects are being overwhelmed with AI generated reports, and some really good ones are being lost in low quality noise. If you have found something, make it defensible and show that you understand the issue, rather than just copied in whatever an AI tool created. Those tend to be immediately discounted as they are seen repeatedly. This doesn't mean AI-assisted is bad, but simple "find me a bug in project X" reports tend to be rejected fast and, if enough false positives arrive, subsequent user reports devalued across all ASF projects Finally, if you are using AI tools, don't be afraid to ask them to fix issues they find too! "here is a likely CVE along with a patch" is far more welcome than "here is a likely CVE" Steve Loughran PhD Researcher Bristol University Cybersecurity Group
