Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a security policy - SECURITY.md file #4328

Closed
JamieSlome opened this issue Feb 27, 2022 · 7 comments
Closed

Add a security policy - SECURITY.md file #4328

JamieSlome opened this issue Feb 27, 2022 · 7 comments

Comments

@JamieSlome
Copy link

Hey there!

I belong to an open source security research community, and a member (@r0hanSH) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

@alvarotrigo
Copy link
Owner

Hey Jamie, sure! I'll add it on the next release!

Meanwhile, feel free to contact me using the contact form.

@alvarotrigo alvarotrigo changed the title Add a security policy Add a security policy - SECURITY.md file Feb 27, 2022
@JamieSlome
Copy link
Author

@alvarotrigo - thanks 👍

I have submitted an e-mail via the contact form. If you want to view the report directly, you can find it here:
https://huntr.dev/bounties/3b9d450c-24ac-4037-b04d-4d4dafbf593a

It is private and only accessible to maintainers with repository write permissions.

@alvarotrigo
Copy link
Owner

alvarotrigo commented Apr 11, 2022

Fixed on v4! 👍

@JamieSlome
Copy link
Author

JamieSlome commented Apr 11, 2022

@alvarotrigo - appreciate your time and response here 👍

Would it be possible to mark the report as valid and confirm the fix? Plus there is also a bounty for the fix too, which you are welcome to :)

@alvarotrigo
Copy link
Owner

Would it be possible to mark the report as valid and confirm the fix?

Done! 👍
Thanks for reporting it and helping out during the process!!

Plus there is also a bounty for the fix too, which you are welcome to :)

Awesome! I didn't know about the bounties!
I'm not sure where the money comes from, but its interesting :)

@JamieSlome
Copy link
Author

@alvarotrigo - not at all, you and @r0hanSH did all the leg work!

Awesome! I didn't know about the bounties!
I'm not sure where the money comes from, but its interesting :)

The funds used for bounties are provided by enterprises that are looking to back the repositories and projects that they depend upon, otherwise, we ourselves fund the research 👍

Also, feel free to drop our badge on your README.md to let your community know they can get bounties for finding vulnerabilities, and of course, the fix bounties are always reserved for maintainers!

huntr.dev

@alvarotrigo
Copy link
Owner

Awesome! It's a great initiative!!
I'll add the budget soon!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants