sensiolabs / BehatPageObjectExtension

MIT License
117 stars 48 forks source link

Trying to get in touch regarding a security issue #139

Closed JamieSlome closed 3 years ago

JamieSlome commented 3 years ago

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

jakzal commented 3 years ago

Feel free to contact me at jakub AT zalas DOT pl. I'm interested to see what security problems might a testing tool have.

jakzal commented 3 years ago

For full visibility, this is where the "vulnerability" that was discovered :)

https://github.com/sensiolabs/BehatPageObjectExtension/blob/6e86a17c7a9ea90ccd8d5ff98beeec24abeb7f7c/features/application/index.php#L16-L17

Nothing to worry about.

DonCallisto commented 3 years ago

Thanks for the update. I was worried and about to ask you more infos. Cheers.