-
Notifications
You must be signed in to change notification settings - Fork 7.2k
Bug: Missing PGP Pubkey in SECURITY.md #15287
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
We don't use GPG in the team in a widespread manner so it'd have created more friction for researchers to reach out ot us. Please reach out via plaintext email and we'll be happy to move the conversation to a more secure channel if need be. |
For security reasons alone, I do expect basic standards like
Also please reopen the issue! |
Do you have an actual report to make? We have been coordinating with security people for years, I find it ironic you chose to ignore our SECURITY.md file which you did read since you mentioned it in your initial message. If you actually have a report to make please follow what's outlined there. |
As a matter of security, I'll not communicate anything related to security through insecure channels - period! There is no excuse for not having a keypair for that at hand!
If you need help with setting it up (among multiple developers) I'm open for that.
|
Then I'm afraid this conversation is over. You seem to be more interested in satisfying your own needs than to working with us in disclosing security problems. If you want to collaborate with us, please read SECURITY.md and get in touch through one of the listed ways, a GH issue is not one of them. |
What happened?
The
SECURITY.md
file does not contain a Public Key for secure communications.Fix:
Platform
Browser / app / sdk version
Firefox 132.0.1 (amd64)
Relevant log output
No response
Reproducibility
More details?
This is security-related, abeit not a security incident, but may inconvenience responsible disclosure.
The text was updated successfully, but these errors were encountered: