Hi BentoML team,
I submitted 8 security advisories on 2026-05-26 via the GitHub Security Advisory workflow.
All 8 are still in Triage state with no maintainer engagement after ~30 days.
Posting here (not in the advisories themselves) because maintainers are not subscribed
to advisory comments by default — I want to make sure this lands in your notifications.
Advisories pending review (full details visible to maintainers only):
Each advisory includes:
- Vulnerable code path (file:line, verified on bentoml==1.4.39)
- Minimal reproduction
- Suggested fix
Happy to help with:
- Deduplication if any overlap with internal findings
- Prioritization by exploitability
- Draft PRs for fixes if useful
I'd appreciate any signal — even "we'll get to this in N weeks" — so I can plan
disclosure timing accordingly. Following industry-standard 90-day disclosure
(would land around 2026-08-24).
cc @parano @aarnphm @ssheng @larme
Thanks,
skyvast404 / 京东 AI 安全实验室
Hi BentoML team,
I submitted 8 security advisories on 2026-05-26 via the GitHub Security Advisory workflow.
All 8 are still in
Triagestate with no maintainer engagement after ~30 days.Posting here (not in the advisories themselves) because maintainers are not subscribed
to advisory comments by default — I want to make sure this lands in your notifications.
Advisories pending review (full details visible to maintainers only):
Each advisory includes:
Happy to help with:
I'd appreciate any signal — even "we'll get to this in N weeks" — so I can plan
disclosure timing accordingly. Following industry-standard 90-day disclosure
(would land around 2026-08-24).
cc @parano @aarnphm @ssheng @larme
Thanks,
skyvast404 / 京东 AI 安全实验室