On Mon, 5 Oct 2026 at 17:05, Aditya <[email protected]> wrote:

> Hi Team,
>
> I'm an independent cybersecurity professional and recently came across a
> security concern affecting one of your external systems.
>
> Could you let me know the appropriate channel for responsible disclosure?
>
> A security contact email, bug bounty page, or disclosure policy would be
> most helpful.
>
> Thanks,
> Aditya
> Cybersecurity Researcher
>


   1. If it's related to github actions, email [email protected] and they
   will act faster; to take things off line.
   2. the ASF doesn't have a bug bounty scheme, though some organisations
   which route reports to the ASF do
   3. all open source projects are being overwhelmed with AI generated
   reports, and some really good ones are being lost in low quality noise. If
   you have found something, make it defensible and show that you understand
   the issue, rather than just copied in whatever an AI tool created. Those
   tend to be immediately discounted as they are seen repeatedly. This doesn't
   mean AI-assisted is bad, but simple "find me a bug in project X" reports
   tend to be rejected fast and, if enough false positives arrive, subsequent
   user reports devalued across all ASF projects

Finally, if you are using AI tools, don't be afraid to ask them to
fix issues they find too!  "here is a likely CVE along with a patch" is far
more welcome than "here is a likely CVE"

Steve Loughran
PhD Researcher
Bristol University Cybersecurity Group

Reply via email to