Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Process for reporting security bugs #255

Closed
Google-Autofuzz opened this issue Jan 30, 2018 · 2 comments
Closed

Process for reporting security bugs #255

Google-Autofuzz opened this issue Jan 30, 2018 · 2 comments
Labels
CVE A security vulnerability bug

Comments

@Google-Autofuzz
Copy link

Hi OpenEXR Team,

As part of our fuzzing efforts at Google, we are interested in understanding the process for reporting potential security issues to your project in a private manner. Could you please advise us if there is a private tracker for these kinds of bugs, or if you prefer them filed in a publicly visible way?

Thanks!

@cary-ilm cary-ilm added the Bug A bug in the source code label Jun 13, 2019
@cary-ilm cary-ilm added this to the Needs Attention milestone Jun 29, 2019
@cary-ilm cary-ilm added CVE A security vulnerability bug and removed Bug A bug in the source code labels Jun 29, 2019
@cary-ilm
Copy link
Member

cary-ilm commented Jul 2, 2019

Now that OpenEXR has been adopted by the Academy Software Foundation, we're looking into the backlog of open issues and revamping the project maintenance process.

There is now a security@openexr.com alias for reporting security vulnerabilities privately to the project steering committee, and the process is addressed in the "How to Report a Security Vulnerability" section in the CONTRIBUTING.md documentation.

I see you filed several bugs as Issues, that's fine, too. We're starting to work through them.

@cary-ilm
Copy link
Member

Closing the issue for now, feel free to re-open or file a new issue if you have further questions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CVE A security vulnerability bug
Projects
None yet
Development

No branches or pull requests

2 participants