Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Should security disclosure page maybe mention rustsec ? #1712

Open
SamB opened this issue Sep 10, 2022 · 0 comments
Open

Should security disclosure page maybe mention rustsec ? #1712

SamB opened this issue Sep 10, 2022 · 0 comments
Labels
A-Content The written content on the website. C-Bug Something isn't working.

Comments

@SamB
Copy link

SamB commented Sep 10, 2022

What needs to be fixed?

First of all: I do not have a vulnerability to report, I was just poking around crates.io and happened to notice that https://crates.io/crates/dwarf didn't have a nice warning box pointing out that the author has abandoned that project in favor of gimli (see https://github.com/philipc/rust-dwarf#readme for the notice, it's at the very beginning of the README), and thought "wasn't there a security tracking database that ought to have an entry about this?", so started clinking links until I found myself at https://www.rust-lang.org/policies/security ... but that clearly was not what I wanted, because I'm not trying to report some hidden vulnerability, just add a publicly posted deprecation to a database ...

Anyway, I was actually looking for rustsec.org and their database.

Page(s) Affected

https://www.rust-lang.org/policies/security

Suggested Improvement

Link to rustsec; describe when it's okay to report things in public and when to report them to security@.

@SamB SamB added A-Content The written content on the website. C-Bug Something isn't working. labels Sep 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-Content The written content on the website. C-Bug Something isn't working.
Projects
None yet
Development

No branches or pull requests

2 participants
@SamB and others