sammycage / lunasvg

SVG rendering and manipulation library in C++
MIT License
866 stars 124 forks source link

How to get in touch regarding a security concern #77

Closed JamieSlome closed 1 year ago

JamieSlome commented 2 years ago

Hey there!

I belong to an open source security research community, and a member (@hdthky) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

sammycage commented 2 years ago

has found an issue, but doesn’t know the best way to disclose it.

You can use the github issue if it doesn't contain any sensitive or private data, or you can just email me directly.

might you kindly add a SECURITY.md file with an email, or another contact method?

I will make out time for it.

Thank You

JamieSlome commented 2 years ago

@sammycage - thanks for your response 👍

It might be easier for you to view the reports directly here: https://huntr.dev/bounties/d623540e-b251-4489-af28-0de189f66d7b/ https://huntr.dev/bounties/48ee7be7-bff5-4c13-aae1-ae36351e75e4/ https://huntr.dev/bounties/28e87590-a097-4e65-a561-5a6c5bdfdb58/ https://huntr.dev/bounties/76de2ad5-a707-481d-bf56-3c4734bf3698/

They are all private and only accessible to you. Let me know if you have any questions.