contao / core-bundle

[READ-ONLY] Contao Core Bundle
GNU Lesser General Public License v3.0
123 stars 58 forks source link

Create SECURITY.md #1723

Closed JamieSlome closed 2 years ago

JamieSlome commented 2 years ago

Hey there!

I belong to an open source security research community, and a member (@ranjit-git) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

github-actions[bot] commented 2 years ago

Thank you for your contribution.

Unfortunately, you have created your issue in the wrong repository, as this is a read-only split repository. Please go to https://github.com/contao/contao and create your issue there.

fritzmg commented 2 years ago

@JamieSlome see https://github.com/contao/contao/security/policy :)

JamieSlome commented 2 years ago

@fritzmg - thanks for the heads up 👍

I will get the report sent over to the security address now. Just a heads up that the report can be found directly here too:

https://huntr.dev/bounties/440306b6-7871-42bf-939b-2dde94325f07

JamieSlome commented 2 years ago

Sent ^