Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trying to get in touch regarding a security issue #340

Open
zidingz opened this issue Aug 26, 2021 · 1 comment
Open

Trying to get in touch regarding a security issue #340

zidingz opened this issue Aug 26, 2021 · 1 comment

Comments

@zidingz
Copy link

zidingz commented Aug 26, 2021

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

@danpat
Copy link
Member

danpat commented Aug 26, 2021

@zidingz This project has no real "owner" - nobody works on it regularly. If you have a patch that fixes the security issue, please submit it as a PR.

Otherwise, I'd just open a ticket that describes the problem. If there is anyone out there using this project that feels it's urgent enough to fix, they'll submit a PR.

Responsible disclosure only works when there's a maintenance team. In this case, there isn't.

If someone out there notices this ticket and is willing to work with @zidingz on the issue, feel free to chime in here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants