pytest-dev / pluggy

A minimalist production ready plugin system
https://pluggy.readthedocs.io/en/latest/
MIT License
1.23k stars 121 forks source link

How to get in touch regarding a security concern #492

Closed psmoros closed 4 months ago

psmoros commented 4 months ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@esmo-ts) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

nicoddemus commented 4 months ago

Thanks @psmoros for reaching out.

Unfortunately we do not have anything security related setup.

For now please send an email to me (oss-pluggy at soliv.dev) and I will bring up the other maintainers as needed.

Pierre-Sassoulas commented 4 months ago

I think pluggy would be eligible for Tidelift incomes. This would also make creating the security process easy (just add a link in security.md)

nicoddemus commented 4 months ago

That's a good idea @Pierre-Sassoulas.

I applied pluggy for lifting, they will answer in a few days.

RonnyPfannschmidt commented 4 months ago

@nicoddemus we ca enable secure incident reporting for the project as well

nicoddemus commented 4 months ago

Ahh well remembered @RonnyPfannschmidt.

@psmoros you can report it here: https://github.com/pytest-dev/pluggy/security

nicoddemus commented 4 months ago

Closing this then.