“There’s a vulnerability in your published code, you have a secret key hardcoded. I cannot open an issue because the code isn’t on GitHub. Can I still apply for a bug bounty.”

At this point I just don’t know anymore.

The code in question, in a repository called blog with a project called demo with an app containing two tests.

git.rdctd.de/timo/blog/src/bra

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.screamingatmyscreen.com/users/fallenhitokiri/statuses/115954441328801330 on your instance and quote it. (Note that quoting is not supported in Mastodon.)