Join Nostr
2026-09-05 16:20:55 UTC

m0wer on Nostr: Found a vulnerability in some LN software with hundreds of stars in GitHub. The repo ...

Found a vulnerability in some LN software with hundreds of stars in GitHub. The repo has no security policy and does not accept private reporting. The maintainer does not advertise his email but managed to found it in some commits. The GPG used to sign them and other stuff is expired but still being used. I did not manage to convince neomutt to encrypt an email with the expired key, because if I changed the system time, then my key was not yet valid xD

Anyway sent an email asking for a fresh GPG key for the report, the maintainer has not answered after a few days.

Do I just open the issue openly? Or what does one do in this cases?