2-report-plugin.yml
2-report-plugin.yml
| Name | About | Labels | Assignees |
|---|---|---|---|
| Report a malicious or abusive plugin | Report a listed plugin that behaves maliciously or violates policy. | plugin-report,triage |
Use this to report a listed plugin (data exfiltration, unexpected
shell/network use, policy violation, etc.). Maintainers triage these
with priority and can unlist a plugin by removing its directory.
For a vulnerability in the tooling/CI/signing or how the app verifies
plugins, use private reporting instead:
https://github.com/vitodeploy/plugins/security/advisories/new
The directory name under plugins/ (e.g. some-vendor-plugin).
Describe the malicious/abusive behavior or policy violation.
File paths, code snippets, observed network/shell activity, logs, screenshots.