temporalio / samples-go

Temporal Go SDK samples
https://docs.temporal.io/docs/go
Other
475 stars 188 forks source link

Reporting a vulnerability #263

Open igibek opened 1 year ago

igibek commented 1 year ago

Hello!

I hope you are doing well!

We are a security research team. Our tool automatically detected a vulnerability in this repository. We want to disclose it responsibly. GitHub has a feature called Private vulnerability reporting, which enables security research to privately disclose a vulnerability. Unfortunately, it is not enabled for this repository.

Can you enable it, so that we can report it?

Thanks in advance!

PS: you can read about how to enable private vulnerability reporting here: https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

badideasforsale commented 1 year ago

Hello, Thanks for mentioning this and wanting to disclose responsibly. We're working on revamping how we take in security findings, and will enable private vulnerability reporting as part of that. However, in the meantime, please send an email to security@temporal.io with your findings and we'll take a look.

Thank you!