pyca / pynacl

Python binding to the Networking and Cryptography (NaCl) library
https://pynacl.readthedocs.io/
Apache License 2.0
1.05k stars 228 forks source link

How to get in touch regarding a security concern #811

Closed psmoros closed 6 days ago

psmoros commented 4 months ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@hussienmisbah) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

alex commented 4 months ago

Vulnerabilities can be reported via https://github.com/pyca/pynacl/security/advisories/new