6eero / NewPass

🔐 NewPass is a free and open source password manager which will allow you to generate and store your passwords securely, saving them locally and encrypting them on your phone's memory
http://www.newpass.solutions/
GNU General Public License v3.0
217 stars 15 forks source link

Missing security contact #43

Closed chrissawyerfan4 closed 5 months ago

chrissawyerfan4 commented 5 months ago

Hi!

As a password manager, I think it is essential to have a private contact method for security issues so fixes can be prepared before people's data is put at risk.

The repository says it is not yet to be trusted. Those who read the readme would know, but if someone gets this software recommended and went straight to the releases page, or downloaded it directly from f-droid or some other method, they couldn't know that it's not yet considered ready for use. (And with how much engagement this repository already has, I doubt there isn't anybody already actually using it despite the warnings.)

Some common options for vulnerability reporting are

To publish the information on how to report vulnerabilities,

Edit: So... GitHub reports I have done a thing which I'm rather certain I haven't done

screenshot of message "chrissawyerfan4 added the bug label just now"

I can't even access that field to change it, so I doubt I could have set it if I had tried... this wasn't me assigning an incorrect label, don't listen to its lies xD

6eero commented 5 months ago

Thanks, i'm working on it!

6eero commented 5 months ago

Done! I've added the security.txt file to the website and the SECURITY.md file to the repository, including the GPG public key. Thanks 💯