Skip to content
Discussion options

You must be logged in to vote

Hi @Marcono1234, GitHub doesn't issue CVEs to forks that are created for security research purposes. The only time we consider issuing a CVE to a forked project is if the original project is unmaintained and the fork is being actively maintained, rather than just created for fixing a specific bug or conducting security research.

There are a number of other CNAs that accept vulnerability reports from independent security researchers, including Vulncheck (which primarily operates in AMER time zones) and VulDB (which primarily operates in EMEA time zones).

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Marcono1234
Comment options

@shelbyc
Comment options

Answer selected by Marcono1234
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants