openedx / wg-security

A repo to keep public issues related to Security Working Group Work
1 stars 1 forks source link

Help Discourse users remember where to report security concerns #35

Open pshiu opened 1 year ago

pshiu commented 1 year ago

A security vulnerability was disclosed publicly on Discourse instead of privately via email.

We discovered this after someone helpfully sent us an email that such a post was made:

https://groups.google.com/a/openedx.org/g/security/c/JPTv43gvXo8

This issue is to add reminders on discuss.openedx.org of where to appropriately report security concerns or vulnerabilities.

pshiu commented 1 year ago

Ideas for where to put the reminders:

Image

pshiu commented 1 year ago

Next steps: