OpenTSDB / opentsdb

A scalable, distributed Time Series Database.
http://opentsdb.net
GNU Lesser General Public License v2.1
5k stars 1.25k forks source link

Where to disclose vulnerabilities #2269

Open CarthageKing opened 1 year ago

CarthageKing commented 1 year ago

Hi - what is the process to report security vulnerabilities for OpenTSDB? These are mainly vulnerabilities identified by Prisma scan.

Is there a secure email or mailing list we can use? Or can we just log it here as an issue?

johann8384 commented 1 year ago

You can log an issue or email me and I can take a look for you.

manolama commented 1 year ago

And my emails in the commits should be up-to-date.

BharathSAi5397 commented 1 year ago

You can log an issue or email me and I can take a look for you.

the guava package needs to be updated to 32.0.0 to resolve some of the vulnerabilities can you guide me how to resolve them.