ethanchewy / PythonBuddy

1st Online Python Editor With Live Syntax Checking and Execution
https://pythonbuddy.com
BSD 3-Clause "New" or "Revised" License
277 stars 84 forks source link

Who to contact for security issues #67

Open benharvie opened 1 year ago

benharvie commented 1 year ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@evanottinger) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

ethanchewy commented 1 year ago

sure - feel free to shoot me an email at 17chiue@gmail.com

I published this back in 2016 so haven't been too active maintaining it but happy to hear any feedback.

ethanchewy commented 1 year ago

Ålso feel free to open a PR with the security fix you have in mind. In the readme, I do mention alternatives that users can use to better secure their own version of PythonBuddy.

ethanchewy commented 1 year ago

I couldn't open the link that you sent via email. It times out when I copy and paste it in incognito.