Hi,
I have a security finding for webhook (a NOT-rule trigger-rule bypass via ParameterNodeError swallow-and-invert logic in the rule evaluator) that I'd like to report responsibly and privately rather than in a public issue.
This repo doesn't have a SECURITY.md or GitHub private vulnerability reporting enabled. Could you either enable Settings > Security > Private vulnerability reporting, or let me know an email/contact I can use?
Thanks!
Hi,
I have a security finding for webhook (a NOT-rule trigger-rule bypass via ParameterNodeError swallow-and-invert logic in the rule evaluator) that I'd like to report responsibly and privately rather than in a public issue.
This repo doesn't have a SECURITY.md or GitHub private vulnerability reporting enabled. Could you either enable Settings > Security > Private vulnerability reporting, or let me know an email/contact I can use?
Thanks!