Security reporting #2602
Replies: 1 comment
|
You used the documented route —
so there isn't a better one on paper. On whether it's watched, the only public signal is that the repo has no published advisories at all — Worth knowing that private advisories have no response SLA and no notification nag — if the maintainer isn't subscribed to that surface, a report can sit indefinitely without anyone actively ignoring it. A comment on your own advisory thread bumps it and is the usual next step before escalating. Failing that, asking in the open the way you have — visible, no details — is the accepted escalation. Issue activity here is heavy and current, so the project is clearly alive even if that particular inbox isn't being read. |
Uh oh!
There was an error while loading. Please reload this page.
Has anyone else reported a security issue through the Security page and heard back?
I filed a private advisory there on 19 July and have not had a reply yet. I am not posting any details here. I am
just trying to work out whether that page is actively monitored, or whether there is a better route for this project.
If anyone has been through this and knows how it normally works here, I would appreciate a pointer.
All reactions