Skip to content

Requesting private vulnerability reporting be enabled #114

Description

@houdini91

Hi, I found a memory-safety issue in rive-runtime's .riv parser (via dynamic analysis with Runzee, an eBPF-based Android security research tool) that reproduces against your real, shipped Android library and would like to report it responsibly. I noticed this repo doesn't have private vulnerability reporting enabled (Settings > Security > "Privately report a security vulnerability") and there's no SECURITY.md, so there's no self-service private channel right now. Could you enable it, or point me to the right contact so I can send details privately? Happy to wait.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions