Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security reports #392

Closed
zowoq opened this issue Jan 22, 2023 · 3 comments · Fixed by nix-community/.github#3
Closed

Security reports #392

zowoq opened this issue Jan 22, 2023 · 3 comments · Fixed by nix-community/.github#3

Comments

@zowoq
Copy link
Contributor

zowoq commented Jan 22, 2023

https://nixos.org/community/teams/security.html

Like the nixos org I suppose we should have a method and some sort of policy for reporting potential security issues with the infra and repos that don't already have their own security reporting or aren't responsive.

Easiest may be taking reports via github itself: Private vulnerability reporting (beta)

Guess an alternative could be encrypted email but we'd probably want a dedicated address that gets forwarded to everyone rather than it potentially being sent directly to one person who isn't responsive.

@zimbatm
Copy link
Member

zimbatm commented Jan 22, 2023

Let's try the github one and see how it goes. They say "route to the repository owner" so maybe this can even work better for us.

@zimbatm
Copy link
Member

zimbatm commented Jan 22, 2023

See also the SECURITY.md to add to the .github repo: https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file

@zowoq
Copy link
Contributor Author

zowoq commented Apr 19, 2023

Easiest may be taking reports via github itself

I've looked at this a little and it seems like it might be a bit complicated for our purposes.

See also the SECURITY.md to add to the .github repo

This with the nix-community admin email seems like the easiest option for initial reporting.

Opened nix-community/.github#3, modified slightly from the Numtide security.md.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants