mirror of
https://github.com/cypht-org/cypht.git
synced 2026-04-25 04:56:03 +03:00
[GH-ISSUE #366] Security Audit #314
Labels
No labels
2fa
I18N
PGP
Security
Security
account
advanced_search
advanced_search
announcement
api_login
authentication
awaiting feedback
blocker
bug
bug
bug
calendar
config
contacts
core
core
devops
docker
docs
duplicate
dynamic_login
enhancement
epic
feature
feeds
framework
github
github
gmail_contacts
good first issue
help wanted
history
history
imap
imap_folders
inline_message
installation
keyboard_shortcuts
keyboard_shortcuts
ldap_contacts
mobile
need-ssh-access
new module set
nux
pop3
profiles
pull-request
question
refactor
release
research
saved_searches
smtp
strategic
tags
tests
themes
website
wordpress
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/cypht#314
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @dumblob on GitHub (Dec 27, 2019).
Original GitHub issue: https://github.com/cypht-org/cypht/issues/366
🗣 Suggestion
As discussed already before in https://github.com/jasonmunro/cypht/issues/11#issuecomment-283608217 , a security audit would be beneficial. Today I heard about Google Patch Rewards extending their offering to all open source projects. Cypht could try to apply 😉.
@Yamakasi commented on GitHub (Dec 28, 2019):
@dumblob I have discussed earlier with Jason to do a security audit which will (hopefully) be funded by me when possible.
Jason has a company he likes to get the audit done with but as I'm not ready to to go production it will be in Q2 of 2020 before I can discuss that with him further :)
@dumblob commented on GitHub (Dec 28, 2019):
@Yamakasi sounds interesting, keep us posted here. Btw. even if you want to fund it, it still makes a lot of sense to gather the funding from several different sites, so you can still take a look at Google Patch Rewards and other private or public sector sponsors.
@jasonmunro commented on GitHub (Jan 7, 2020):
@dumblob this looks worth giving it a shot. Even the "small" tier would likely cover a full security audit (based on old unofficial quotes but still). I will check out the application process and update this issue when I do.
@marclaporte commented on GitHub (May 31, 2020):
@Yamakasi : any news?
Thanks!
@marclaporte commented on GitHub (Jul 31, 2022):
Anyone want to lead this?
@marclaporte commented on GitHub (Oct 22, 2022):
I am ready to co-sponsor a security audit on Cypht. We just need one more co-sponsor and we can proceed. Please contact me if you are willing to also be a co-sponsor.
@dumblob commented on GitHub (Nov 8, 2022):
IDK - Mozilla again 😉?
@marclaporte commented on GitHub (Nov 8, 2022):
Ok, looking for a volunteer to draft up the request/proposal.