Skip to content

Update all-for-one.md#382

Closed
gagliardetto wants to merge 4 commits intogithub:mainfrom
gagliardetto:patch-2
Closed

Update all-for-one.md#382
gagliardetto wants to merge 4 commits intogithub:mainfrom
gagliardetto:patch-2

Conversation

@gagliardetto
Copy link
Copy Markdown
Contributor

@gagliardetto gagliardetto commented Jun 10, 2021

This PR is a draft of how I would address the major points of confusion for bug bounty application submitters, and remove obstacles that might discourage and create friction for anyone considering to write and submit a query.

Preview: https://github.com/gagliardetto/securitylab/blob/patch-2/.github/ISSUE_TEMPLATE/all-for-one.md

@gagliardetto
Copy link
Copy Markdown
Contributor Author

@JarLob JarLob requested a review from xcorail July 13, 2021 08:30
Copy link
Copy Markdown
Contributor

@xcorail xcorail left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @gagliardetto thanks for this PR

Sorry for all the suggestions, it's a bit messy but TL;DR is

  • Move back the CVE requirement up into the Results section
  • Move down the social section
  • Align the Results section instructions to the CVE requirement

Let's iterate after this first pass, as all the suggestions make the PR difficult to read

Comment on lines +39 to +52
## 3. Social

### Instructions ❓

Are you planning to discuss your query publicly? (Blog Post, social networks, etc).

**We would love to [help you] spread the word about the good work you are doing.**

### Your answer 👇

- [ ] Yes
- [ ] No
- [ ] Yes, I already have: [link](link)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## 3. Social
### Instructions ❓
Are you planning to discuss your query publicly? (Blog Post, social networks, etc).
**We would love to [help you] spread the word about the good work you are doing.**
### Your answer 👇
- [ ] Yes
- [ ] No
- [ ] Yes, I already have: [link](link)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved to bottom

- Description: URL to vulnerable code

- CVE-20nn-nnnnn
## 5. CVE ID(s)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## 5. CVE ID(s)

## 5. CVE ID(s)

## Report
### Instructions ❓
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
### Instructions ❓

### Instructions ❓

*Describe the vulnerability. Provide any information you think will help GitHub assess the impact your query has on the open source community.*
List the CVE ID(s) associated with this vulnerability. GitHub will automatically link CVE IDs to the [GitHub Advisory Database](https://github.com/advisories).
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
List the CVE ID(s) associated with this vulnerability. GitHub will automatically link CVE IDs to the [GitHub Advisory Database](https://github.com/advisories).

- [ ] Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc). *We would love to have you spread the word about the good work you are doing*

## Result(s)
### Your answer 👇
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
### Your answer 👇

- Answer: ...
1. How have you reduced the number of **false positives**?
- Answer: ...
1. Etc.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
1. Etc.
1. Other information?

Comment on lines +71 to +72
- [ ] The vulnerability is already **fixed and disclosed**.
- Description: URL to vulnerable code
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- [ ] The vulnerability is already **fixed and disclosed**.
- Description: URL to vulnerable code


- [ ] I will provide the result(s) **privately** to the Security Lab.

**OR**
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
**OR**

- Anyway, we're here for **automating things away** and if you want to leave the heavy lifting of finding and notifying vulnerable repositories' owners to GitHub security bots, that's fine with us.
- But in any case, we need proof that you **did your own reaserch** on [real projects], and succeeded in finding at least one **true positive result [through your query]**, proving that is it a **real vulnerability** that happens in real apps (and not a baseless assumption).

### Your answer 👇 (select one)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
### Your answer 👇 (select one)
### Your answer 👇

- But in any case, we need proof that you **did your own reaserch** on [real projects], and succeeded in finding at least one **true positive result [through your query]**, proving that is it a **real vulnerability** that happens in real apps (and not a baseless assumption).

### Your answer 👇 (select one)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Existing CVEs that my query would have been able to find if they weren't already fixed:
1. CVE-20nn-nnnnn
- Vulnerabilities that my query found and then resulted in a CVE:
1. CVE-20nn-nnnnn
**OR**

@xcorail
Copy link
Copy Markdown
Contributor

xcorail commented Nov 8, 2021

👋🏾 @gagliardetto
Note that this PR will need to be closed / revisited after this one, which is moving the template from classical .md template to an issue form

cc @pwntester

@gagliardetto
Copy link
Copy Markdown
Contributor Author

Thank you @xcorail !

Sorry, I completely forgot about this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants