dvidelabs / flatcc

FlatBuffers Compiler and Library in C for C
Apache License 2.0
645 stars 184 forks source link

Missing Security policy #298

Open abnara opened 19 hours ago

abnara commented 19 hours ago

I wanted to know if there is a way to submit security issues. There is no Security.md file in the repo. This is a requirement for me to be able to use the product. Are there plans to add a security policy?

mikkelfj commented 2 hours ago

This is not exactly what you are asking for, but there is: https://github.com/dvidelabs/flatcc/blob/master/doc/security.md

There are no plans to add a security policy as there has been no pressing need. But it is possible to contact repo owner (me) directly by email, just look it up.

I don't feel like setting up a dedicated email for this, but you have any suggestions be my guest. There have historically been a few issues that could have warranted a CVE alert but they have been fixed timely and https://github.com/dvidelabs/flatcc/blob/master/CHANGELOG.md is the best place to stay on top of issues.