PrefectHQ / prefect

Prefect is a workflow orchestration framework for building resilient data pipelines in Python.
https://prefect.io
Apache License 2.0
15.82k stars 1.55k forks source link

Who to contact for security issues #11517

Closed psmoros closed 8 months ago

psmoros commented 8 months ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@mik0w) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

psmoros commented 8 months ago

Sorry about that, we already have an email

chrisguidry commented 6 months ago

Hi @psmoros, we have just updated our SECURITY.md to have the correct email address bugbounty@prefect.io, sorry, the wrong folks were getting the emails before.