- Notifications
You must be signed in to change notification settings - Fork9.9k
Security: desktop/desktop
Security
SECURITY.md
GitHub takes the security of our software products and services seriously, including the open source code repositories managed through our GitHub organizations, such asGitHub.
If you believe you have found a security vulnerability in this GitHub-owned open source repository, you can report it to us in one of two ways.
If the vulnerability you have found isnotin scope for the GitHub Bug Bounty Program or if you do not wish to be considered for a bounty reward, please report the issue to us directly usingprivate vulnerability reporting.
If the vulnerability you have found isin scope for the GitHub Bug Bounty Program and you would like for your finding to be considered for a bounty reward, please submit the vulnerability to us throughHackerOne in order to be eligible to receive a bounty award.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Thanks for helping make GitHub safe for everyone.
- Maliciously crafted file renames can lead to information disclosureGHSA-f234-7hj3-vr8j published
May 21, 2025 byniikLow - Maliciously crafted remote URLs could lead to credential leakGHSA-36mm-rh9q-cpqq published
Jan 15, 2025 byniikModerate - Credentials transmitted to wrong hosts in repositories with submodules on different hosts than the parent repositoryGHSA-2g23-3f32-64gr published
May 23, 2024 byniikHigh