Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Write a security policy / nominate security contacts #641

Open
miceg opened this issue May 7, 2024 · 5 comments
Open

Write a security policy / nominate security contacts #641

miceg opened this issue May 7, 2024 · 5 comments

Comments

@miceg
Copy link
Contributor

miceg commented May 7, 2024

Feature description

This repository doesn't list any security policy or security contacts.

GeoServer has some: https://github.com/geoserver/geoserver/blob/main/SECURITY.md

Additional context

I have discovered a low-severity security issue affecting Kartoza's GeoServer Docker image, which is triggered by something in this repository.

I'm in contact with GeoServer folks about the issue, and they've asked me to not share details publicly.

I think Kartoza should be brought into the loop.

@NyakudyaA
Copy link
Collaborator

@miceg There seems to be a couple of these security issues as indicated here https://github.com/kartoza/docker-geoserver/security/code-scanning, If it's something we can fix please send us a direct email as well. Most of these seem to come from jars

@miceg
Copy link
Contributor Author

miceg commented May 8, 2024

I don't have access to that page – but I am pretty confident it's not something a security scanner will find 😄

I'll ask to have you looped in the discussion, thanks 😄

@NyakudyaA
Copy link
Collaborator

@miceg ping me @addloe@gmail.com and I can share the logs

@jodygarnett
Copy link

@Admire Nyakudya if you or another Kartoza employee is interested in volunteering on geoserver-security we would appreciate the assistance.

The value proposition is:

  • Participants help out evaluating and reproducing vulnerabilities as they are reported (providing value to the project)
  • Earn the insight to take care of their contracts and products in a responsible manner (providing value to their customers)

Thanks

@NyakudyaA
Copy link
Collaborator

Thanks @jodygarnett I can participate

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants