getformwork / formwork

🏗 A flat file-based Content Management System (CMS) to build and manage sites with simplicity
MIT License
51 stars 12 forks source link

How to get in touch regarding a security concern #378

Closed benharvie closed 1 year ago

benharvie commented 1 year ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@xanhacks) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

giuscris commented 1 year ago

Hello @benharvie 👋 , I've created SECURITY.md, with all the information you need to report a security concern. Thank you.