Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable private reporting of vulnerabilities or document how to report vulnerabilities #301

Closed
maxammann opened this issue Jul 26, 2023 · 1 comment

Comments

@maxammann
Copy link

I wanted to report a security issue, but failed to find a contact. @dvdplm did not respond to an email I sent. I am aware that this repository is no longer maintained, but first wanted to confirm that posting the issue as GitHub issue is fine.

There are at least two possibilities:

If there is no response to this issue until 21. of August 2023, a GitHub issue about the vulnerability will be created.

@vkgnosis
Copy link
Member

I have been the de facto maintainer for the last 1.5 years.

Post the vulnerability in a public issue. There is no one responsible enough for this project to act on private reports in a timely manner. Better to let everyone know about it. I'm going to make a change to the Readme to make the maintenance status clearer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants