-
-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vulnerability report #1126
vulnerability report #1126
Comments
here only. fill the template and you can submit the report here |
I would advise against disclosing security vulnerabilities in a public manner before there is fix. please confirm that you want me to disclose details of the vulnerability here. I'll be happy to provide a detailed report and try to help to push a fix as soon as possible . |
thanks for the alert. no don't report here.
|
How severe is this issue? Is it in an NPM module that affects local development? It is hard to imagine any issue with static HTML (markdown) sites being insecure. Docsify sites are purely static by default, with no user information (or did I miss something?). @anikethsaha Maybe we can make a security issue template, and it can specify contact instructions there. |
we need to set up a policy here |
Ah cool, I didn't know about that. |
true, but we do support GA, codefund plugins and markdown may contain embedded files so it may be harmful in those cases. not sure though 😅 . I will still suggest reporting first in snyk for any cases even if it is in our dependencies, |
I'll get in touch with snyk team asap. I'll contact you through email for a detailed report |
please let me know if I can contribute in any way |
great. 👍
contribution of any kind are always welcome. you can share some idea or submit as a policy for better approach. We can discuss there |
The Snyk team have verified the vulnerability. they will try to get in touch with you to discuss a fix. if you want to close this issue, you can always reach me at amin.sharifi691@gmail.com. |
Thanks a lot for the reports and responses.
sure. Thanks 👍 |
I think it's better to keep it open until a response from snyk just to mark it. 👍 |
my pleasure |
I agree |
I can't imagine the vulnerability in Docsify either. |
I got a mail from |
Bug Report
I have found a security vulnerability in docsify.sj. How would you like me to report it?
Steps to reproduce
What is current behaviour
What is the expected behaviour
Other relevant information
Bug does still occur when all/other plugins are disabled?
Your OS:
Node.js version:
npm/yarn version:
Browser version:
Docsify version:
Docsify plugins:
Please create a reproducible sandbox
Mention the docsify version in which this bug was not present (if any)
The text was updated successfully, but these errors were encountered: