Skip to content
This repository has been archived by the owner on Jun 5, 2024. It is now read-only.

Responsible disclosure policy #78

Closed
JamieSlome opened this issue Jun 30, 2022 · 5 comments
Closed

Responsible disclosure policy #78

JamieSlome opened this issue Jun 30, 2022 · 5 comments

Comments

@JamieSlome
Copy link

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@J-GainSec) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

@inoda
Copy link
Owner

inoda commented Jul 30, 2022

@JamieSlome Feel free to just share the issue here.

@JamieSlome
Copy link
Author

@inoda - sure, both issues can be found here:

https://huntr.dev/bounties/31284e3a-ed7b-4896-817d-8d340f4d3862/
https://huntr.dev/bounties/dbbf87f0-d77b-4b1b-a28f-6d8ef424e8f0/

Both are currently private and only accessible by you 👍

@inoda
Copy link
Owner

inoda commented Aug 1, 2022

@JamieSlome Can you just share the issue here publicly? I understand this is a mechanism to get adoption for your site but I'm not interested in making an account

@inoda
Copy link
Owner

inoda commented Aug 1, 2022

Seems like this got moved to #82

@inoda inoda closed this as completed Aug 1, 2022
@JamieSlome
Copy link
Author

@inoda - I have made both reports public at the same URLs.

We do not make reports private for adoption, but purely because many maintainers don't want reports public by default. We allow maintainers to access reports using magic URLs, where sign-up is not required at all. This is why we first request an e-mail, so we can send a magic URL to view the reports 👍

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants