Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to get in touch regarding a security concern #465

Closed
psmoros opened this issue Feb 4, 2023 · 7 comments
Closed

How to get in touch regarding a security concern #465

psmoros opened this issue Feb 4, 2023 · 7 comments
Assignees
Labels

Comments

@psmoros
Copy link

psmoros commented Feb 4, 2023

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@nightfury99) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

@AntoineLelaisant
Copy link

Thanks for the feedback! I just configure the security policy https://github.com/KnpLabs/snappy/blob/master/SECURITY.md. Looking forward to hear from you!

@nightfury99
Copy link

nightfury99 commented Mar 17, 2023 via email

@AntoineLelaisant
Copy link

Fixed in #469

@psmoros
Copy link
Author

psmoros commented Mar 17, 2023

Hi @AntoineLelaisant can you please attribute credit to @nightfury99 instead of me? Also should we attribute a CVE for the finding? :)

@AntoineLelaisant
Copy link

Credits updated 😉!

We already asked for a CVE from Github to be generated. It should be provided within 3 working days.

Thanks for your reporting!

@nightfury99
Copy link

nightfury99 commented Mar 29, 2023 via email

@nightfury99
Copy link

nightfury99 commented Apr 1, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants