豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

Security: dependabot/dependabot-core

SECURITY.md

GitHub takes the security of our software products and services seriously, including the open source code repositories managed through our GitHub organizations, such as GitHub.

If you believe you have found a security vulnerability in this GitHub-owned open source repository, you can report it to us in one of two ways.

Dependabot is in scope for the GitHub Bug Bounty Program. If you would like your finding to be considered for a bounty reward, please submit the vulnerability to us through HackerOne in order to be eligible to receive a bounty award.

If you do not wish to be considered for a bounty reward, please report the issue to us directly using private vulnerability reporting.

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Thanks for helping make GitHub safe for everyone.