logseq / marketplace

A centralized packages manager for Logseq marketplace plugins.
MIT License
247 stars 271 forks source link

How to report a security‒vulnerable plugin registered in the Marketplace? #578

Open kkm000 opened 3 weeks ago

kkm000 commented 3 weeks ago

The title says it. I obviously can't disclose the plugin name and the nature of the vulnerability publicly, but the plugin should be pulled off the Marketplace until the issue is resolved, and active users warned. What is the security contact for the Marketplace?

Other "marketplaces" (VS Code/VS plugins, browser extensions, Google Workplace extensions, you name it) have a Report button, and reports are always promptly acted upon with due diligence. Hint, hint. :-)

X-Ref: ‘Add the security “Report Plugin” button in Marketplace’, logseq discussion board

xyhp915 commented 3 weeks ago

Thank you for your suggestion. We will add this entrance soon in app.

Also, just added the relevant instructions in the README. https://github.com/logseq/marketplace?tab=readme-ov-file#how-to-report-an-unavailable-or-malicious-plugin