-
Notifications
You must be signed in to change notification settings - Fork 45
Security contact incorrect #127
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
@chimosky what do you recommend? |
Creating a new alias - security@sugarlabs.org - can work, but the question is, who do we want to see these alerts? systems@lists.sugarlabs.org comes to mind, but I'm skeptical as most people on the list don't manage our GH repos, but it does give visibility to the issue. If anyone is fine with receiving and looking into these issues then we can create an alias and have it point at them. |
systems@lists.sugarlabs.org is public, archived, using that would violate the conventions on privacy of disclosure. https://lists.sugarlabs.org/archive/systems/ It should be an office-bearer of the organisation, or one of their delegates. Also remember to consider not having a GitHub security contact, requiring all disclosures to be public or to office-bearers in private. |
I agree, we can have someone on the board handle this. |
Reporting security issues through GitHub (such as via dependabot discovery) on this repository redirects to security@sugarlabs.org, which bounces.
Either;
Thanks.
The text was updated successfully, but these errors were encountered: