openedx / wg-security

A repo to keep public issues related to Security Working Group Work
1 stars 0 forks source link

Research how to discourage public disclosure of unresolved security vulnerabilities #7

Open pshiu opened 1 year ago

pshiu commented 1 year ago

https://github.com/openedx/tcril-engineering/issues/674 was published to the public before its vulnerability was resolved.

No issue here because NPM had already auto-rotated our keys for us! However, we may want to look into making it clearer for requestors how to file vulnerabilities securely, or for automating that process.

Ideas: