Potential security issue
psmoros opened this issue ยท 5 comments
Hello ๐
I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@Benasin) has found a potential issue, which I would be eager to share with you.
Could you add a SECURITY.md
file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.
Looking forward to hearing from you ๐
(cc @huntr-helper)
That's a good idea! Let me read some docs about GitHub's interface for this. In the meantime, my public email address is posted on my profile (@kurtmckee) and you can send information to me via that route. Thanks!
Hi guys, are there any updates on the Security Issue?
Yes, I told you to send an email to my email address.
Having an official point of contact is super important when someone
finds a vulnerability and wants to responsibly report it.
The "Security" button on GitHub repos shows what a project's
Security Policy is as defined by the Security.md file.
You are correct, and I haven't implemented it yet. I have responded how this particular issue can be reported in the meantime.