CERTCC / CERT-Guide-to-CVD

Content for the CERT Guide to Coordinated Vulnerability Disclosure
https://certcc.github.io/CERT-Guide-to-CVD/
Other
7 stars 5 forks source link

How to report vuls in open source software? #12

Open ahouseholder opened 1 year ago

ahouseholder commented 1 year ago

Github supports privately reporting security information, see

https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability

The guide should say something about this & any other methods we come across specifically for open source projects.