mirror of
https://github.com/ArchiveBox/ArchiveBox.git
synced 2026-04-26 01:26:00 +03:00
[GH-ISSUE #934] Who to contact for security issues #3597
Labels
No labels
expected: maybe someday
expected: next release
expected: release after next
expected: unlikely unless contributed
good first ticket
help wanted
pull-request
scope: all users
scope: windows users
size: easy
size: hard
size: medium
size: medium
status: backlog
status: blocked
status: done
status: idea-phase
status: needs followup
status: wip
status: wontfix
touches: API/CLI/Spec
touches: configuration
touches: data/schema/architecture
touches: dependencies/packaging
touches: docs
touches: js
touches: views/replayers/html/css
why: correctness
why: functionality
why: performance
why: security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/ArchiveBox#3597
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @JamieSlome on GitHub (Feb 23, 2022).
Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/934
Hey there!
I belong to an open source security research community, and a member (@noobexploiterhuntrdev) has found an issue, but doesn’t know the best way to disclose it.
If not a hassle, might you kindly add a
SECURITY.mdfile with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.Thank you for your consideration, and I look forward to hearing from you!
(cc @huntr-helper)
@pirate commented on GitHub (Mar 13, 2022):
email:
<REDACTED>(use this page instead now) or twitter DM@ArchiveBoxApp@JamieSlome commented on GitHub (Mar 13, 2022):
@pirate - thanks for sharing this 👍
I will get an e-mail over to you shortly. In the meantime, you can view the reports directly here:
https://huntr.dev/bounties/a640b898-4350-4289-84e9-8dc3f5f15e48/
https://huntr.dev/bounties/104c4e7f-6301-46f1-94e2-aa8aba0a07fe/
They are both private and only accessible to maintainers with repository write permissions. If you have any questions, let me know.
@pirate commented on GitHub (Jan 19, 2024):
For anyone who sees this in the future, security reports are now handled through github: https://github.com/ArchiveBox/ArchiveBox/security