linlinjava / litemall

又一个小商城。litemall = Spring Boot后端 + Vue管理员前端 + 微信小程序用户前端 + Vue用户移动端
MIT License
19.25k stars 7.21k forks source link

Create SECURITY.md #495

Closed zidingz closed 3 years ago

zidingz commented 3 years ago

Hey there!

I belong to an open source security research community, and a member (@michaellrowley) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

linlinjava commented 3 years ago

7d79dfc68c36bd31e30c72acfdfd366f932bde0f

JamieSlome commented 2 years ago

@linlinjava - thanks for creating the policy! 👍

We sent a couple of e-mails back in October but never heard back. You can view the report directly here: https://huntr.dev/bounties/ddaae70a-d91f-4695-a8c2-589fb6557784/

It is private and only accessible to you :)

linlinjava commented 2 years ago

@JamieSlome thanks