Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document how to report a security vulnerability #4599

Closed
edmorley opened this issue Mar 30, 2017 · 10 comments · Fixed by #7118
Closed

Document how to report a security vulnerability #4599

edmorley opened this issue Mar 30, 2017 · 10 comments · Fixed by #7118

Comments

@edmorley
Copy link
Contributor

I have an issue that I believe should be reported non-publicly (it may end up being deemed safe enough to report via GitHub but I'd rather ask first), however I couldn't find a security bug reporting process documented on any of:
https://github.com/webpack/webpack/blob/master/README.md
https://github.com/webpack/webpack/blob/master/CONTRIBUTING.md
https://webpack.js.org/support/
https://webpack.js.org/development/

Please could a process be created/documented?

Thanks!

@sokra
Copy link
Member

sokra commented Mar 30, 2017

You can send me a mail.

@webpack-bot
Copy link
Contributor

This issue had no activity for at least half a year.

It's subject to automatic issue closing if there is no activity in the next 15 days.

@edmorley
Copy link
Contributor Author

.

@webpack-bot
Copy link
Contributor

This issue had no activity for at least half a year.

It's subject to automatic issue closing if there is no activity in the next 15 days.

@edmorley
Copy link
Contributor Author

.

@alexander-akait
Copy link
Member

/cc @sokra can we integrate webpack.js.org with Google Business Email and create security@webpack.js.org email? Also create SECURITY.md with contents:

# Reporting Security Issues

If you discover a security issue in webpack, please report it by sending an
email to [security@webpack.js.org](security@webpack.js.org).

This will allow us to assess the risk, and make a fix available before we add a
bug report to the GitHub repository.

Thanks for helping make webpack safe for everyone.

@alexander-akait
Copy link
Member

BTW we can add this file right now with you public email

@TheLarkInn
Copy link
Member

Also you can reach out to webpack@opencollective.com which will go to all maintainers.

@edmorley
Copy link
Contributor Author

Many thanks :-)

@webpack-bot
Copy link
Contributor

For maintainers only:

  • webpack-4
  • webpack-5
  • bug
  • critical-bug
  • enhancement
  • documentation
  • performance
  • dependencies
  • question

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants