expressjs / security-wg

Express.js Security Working Group
MIT License
10 stars 3 forks source link

Proposal: add repository security advisory #30

Open bjohansebas opened 2 weeks ago

bjohansebas commented 2 weeks ago

GitHub has a feature that allows creating a draft security advisory to privately discuss and fix a security vulnerability, similar to how issue templates work.

For example, Next.js has this feature enabled: image

I believe this would improve the process of reporting potential vulnerabilities in Express and its packages.

ref:

UlisesGascon commented 2 weeks ago

Yep! We will add this to all the repos at some point (hope soon). I will transfer the issue to the Security-wg for execution :+1: