I have a reproducible access-control issue in the IAM admin API that affects RELEASE.2026-09-16T00-00-00Z (reproduced on the current Docker Hub image). It is related to the scope of an inherited fix listed in your security advisory ledger.
SECURITY.md asks for reports through the private GitHub security advisory workflow, but private vulnerability reporting appears to be disabled on this repository: GET /repos/pgsty/silo/private-vulnerability-reporting returns {"enabled": false}, and the "new advisory" link offers no report form.
Following SECURITY.md, I'm not publishing any details here. Could you enable private vulnerability reporting, or share a private contact? A self-contained reproduction script and its output are ready to send.
I have a reproducible access-control issue in the IAM admin API that affects
RELEASE.2026-09-16T00-00-00Z(reproduced on the current Docker Hub image). It is related to the scope of an inherited fix listed in your security advisory ledger.SECURITY.md asks for reports through the private GitHub security advisory workflow, but private vulnerability reporting appears to be disabled on this repository:
GET /repos/pgsty/silo/private-vulnerability-reportingreturns{"enabled": false}, and the "new advisory" link offers no report form.Following SECURITY.md, I'm not publishing any details here. Could you enable private vulnerability reporting, or share a private contact? A self-contained reproduction script and its output are ready to send.