Skip to content

Who to contact for security issues聽#67

Description

@benharvie

Hello 馃憢

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@evanottinger) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 馃憤

(cc @huntr-helper)

Activity

  1. ethanchewy commented on Dec 11, 2022

    @ethanchewy
    Owner

    sure - feel free to shoot me an email at 17chiue@gmail.com

    I published this back in 2016 so haven't been too active maintaining it but happy to hear any feedback.

  2. ethanchewy commented on Dec 11, 2022

    @ethanchewy
    Owner

    脜lso feel free to open a PR with the security fix you have in mind. In the readme, I do mention alternatives that users can use to better secure their own version of PythonBuddy.

  3. ethanchewy commented on Dec 11, 2022

    @ethanchewy
    Owner

    I couldn't open the link that you sent via email. It times out when I copy and paste it in incognito.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions