doy / spreadsheet-parsexlsx

parse XLSX files
http://metacpan.org/release/Spreadsheet-ParseXLSX
27 stars 35 forks source link

How to get in touch regarding a security concern #103

Open psmoros opened 1 year ago

psmoros commented 1 year ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@haile01) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

phvietan commented 8 months ago

Hello, I'm a researcher at huntr.com too and also submitted a vuln by the username https://huntr.com/users/phvietan/ . Could you also check my report as well ? Again, thank you for keeping OSS world more secure.

Thank you

MichaelDaum commented 8 months ago

Hi, I've taken over maintenance of this plugin with permissions by the original author. Please contact me in case of new security findings. Thanks.