Hi, I found a memory-safety issue in rive-runtime's .riv parser (via dynamic analysis with Runzee, an eBPF-based Android security research tool) that reproduces against your real, shipped Android library and would like to report it responsibly. I noticed this repo doesn't have private vulnerability reporting enabled (Settings > Security > "Privately report a security vulnerability") and there's no SECURITY.md, so there's no self-service private channel right now. Could you enable it, or point me to the right contact so I can send details privately? Happy to wait.
Thanks!
Hi, I found a memory-safety issue in rive-runtime's .riv parser (via dynamic analysis with Runzee, an eBPF-based Android security research tool) that reproduces against your real, shipped Android library and would like to report it responsibly. I noticed this repo doesn't have private vulnerability reporting enabled (Settings > Security > "Privately report a security vulnerability") and there's no SECURITY.md, so there's no self-service private channel right now. Could you enable it, or point me to the right contact so I can send details privately? Happy to wait.
Thanks!