facebook / yoga

Yoga is an embeddable layout engine targeting web standards.
https://yogalayout.dev/
MIT License
17.31k stars 1.43k forks source link

Where are security vulnerabilities reported? #1020

Closed mrdewitt closed 7 months ago

mrdewitt commented 4 years ago

Report

I am thinking of integrating with Yoga, and am wondering where security vulnerabilities are disclosed. Do you use github's security features? Are they posted with a CVE, and if so do you have a CPE prefix that I can use?

I see that the security policy page links to facebook.com/whitehat but that does not include information about disclosures.

mrdewitt commented 4 years ago

Any updates available here?

ngyikp commented 4 years ago

Facebook does disclose valid vulnerabilities in their open source projects by issuing CVEs, example past projects include HHVM, Proxygen and Hermes.

mrdewitt commented 4 years ago

I am hoping for a response from an owner of this project, I'd prefer to have positive confirmation than to make an assumption.

NickGerleman commented 7 months ago

We would disclose any vulnerabilities. Yoga has so far not had any.