cds-snc / platform-forms-client

NextJS application that serves the public-facing website for Forms
https://forms-staging.cdssandbox.xyz/
MIT License
34 stars 13 forks source link

Setting up alerts for 0-day vulnerabilities #3038

Open wmoussa-gc opened 9 months ago

wmoussa-gc commented 9 months ago

Context A zero-day is a vulnerability or security hole in a computer system unknown to its owners, developers or anyone capable of mitigating it. Until the vulnerability is remedied, threat actors can exploit it in a zero-day exploit, or zero-day attack.

Goal As a Forms developer, I want to set up an alert for 0-day vulnerabilities, so that Ii can be notified immediately when such vulnerabilities are discovered.

Standard Operating Procedure If a zero-day vulnerability is affecting Forms:

wmoussa-gc commented 7 months ago

Conversation with security team: https://gcdigital.slack.com/archives/CS2L5CHKK/p1707403949309809