[GH-ISSUE #2159] Missing point of contact for security issues #906

Closed
opened 2026-03-16 00:49:57 +03:00 by kerem · 3 comments
Owner

Originally created by @pspacek on GitHub (Feb 29, 2024).
Original GitHub issue: https://github.com/hickory-dns/hickory-dns/issues/2159

It's unclear how to report security issues while keeping all the information confidential.

Examples from other DNS servers:

Originally created by @pspacek on GitHub (Feb 29, 2024). Original GitHub issue: https://github.com/hickory-dns/hickory-dns/issues/2159 It's unclear how to report security issues while keeping all the information confidential. Examples from other DNS servers: - https://github.com/PowerDNS/pdns/?tab=security-ov-file#readme - https://gitlab.isc.org/isc-projects/bind9/-/blob/main/SECURITY.md - https://www.nlnetlabs.nl/security-report/
kerem closed this issue 2026-03-16 00:50:02 +03:00
Author
Owner

@djc commented on GitHub (Feb 29, 2024):

I suggest we enable GitHub's built-in private security vulnerability reporting. @bluejekyll agreed?

<!-- gh-comment-id:1971407441 --> @djc commented on GitHub (Feb 29, 2024): I suggest we enable GitHub's built-in private security vulnerability reporting. @bluejekyll agreed?
Author
Owner

@bluejekyll commented on GitHub (Feb 29, 2024):

agreed.

<!-- gh-comment-id:1971705615 --> @bluejekyll commented on GitHub (Feb 29, 2024): agreed.
Author
Owner

@djc commented on GitHub (Mar 1, 2024):

I've enabled private vuln reporting and drafted a basic initial security policy in #2163.

<!-- gh-comment-id:1972923668 --> @djc commented on GitHub (Mar 1, 2024): I've enabled private vuln reporting and drafted a basic initial security policy in #2163.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hickory-dns#906
No description provided.