richardbarran / django-photologue

A customizable plug-in photo gallery management application for the Django web framework.
BSD 3-Clause "New" or "Revised" License
674 stars 239 forks source link

Create SECURITY.md #223

Closed JamieSlome closed 2 years ago

JamieSlome commented 2 years ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@domiee13) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

richardbarran commented 2 years ago

Hi @JamieSlome - I've added a SECURITY.md as suggested. I look forward to hearing details of the security issue.

JamieSlome commented 2 years ago

Thanks, @richardbarran 👍

I just used the form, but just for reference, the report can be found here:

https://huntr.dev/bounties/cd8b71df-8e92-4f07-b60d-c58ae757f5bc/

domiee13 commented 1 year ago

Hello @richardbarran

Do you have any update about my report ?