matrix-org / rageshake

Bug report server
Apache License 2.0
30 stars 12 forks source link

Customer is asking for OWASP docs around how rageshake reports are collected #58

Open benparsons opened 2 years ago

benparsons commented 2 years ago

Is your feature request related to a problem? Please describe.

There is no problem, however customer is asking on behalf of their end-user for reassurances that we are using security best practices when collecting data. OWASP (https://owasp.org/www-project-secure-coding-practices-quick-reference-guide/migrated_content) is the framework they are pointing to but presumably this would be fairly standard.

Describe the solution you'd like

Some documentation to say this project uses best practices.

richvdh commented 1 year ago

"It uses best practices".

The link in the description is now a 404: are there particular areas of concern which we might be able to help with?