“There’s a vulnerability in your published code, you have a secret key hardcoded. I cannot open an issue because the code isn’t on GitHub. Can I still apply for a bug bounty.”
At this point I just don’t know anymore.
The code in question, in a repository called blog with a project called demo with an app containing two tests.