tianshiyeben / wgcloud

Linux运维监控工具,支持系统硬件信息,内存,cpu,温度,磁盘空间及IO,硬盘smart,系统负载,网络流量等监控,服务接口,大屏展示,拓扑图,进程监控,端口监控,docker监控,文件防篡改,日志监控,数据可视化,web ssh,堡垒机,指令下发批量执行,Linux面板(探针),SNMP,故障告警,计划任务,账号管理,资产管理
http://www.wgstart.com
Apache License 2.0
4.6k stars 836 forks source link

Who to contact for security issues #41

Closed JamieSlome closed 2 years ago

JamieSlome commented 2 years ago

Hey there!

I belong to an open source security research community, and a member (@hi-unc1e) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

tianshiyeben commented 2 years ago

Thank you very much. Please send the question to email tianshiyeben@qq.com

JamieSlome commented 2 years ago

@tianshiyeben - we actually sent an e-mail to you about 1 hour ago to the mentioned e-mail address. Did you receive this?

Just for reference, you can find the report here. It is private and only accessible to you 👍 Let me know if you have any questions.

tianshiyeben commented 2 years ago

Thank you very much. I have received it. I will think about how to deal with this problem

JamieSlome commented 2 years ago

@tianshiyeben - great! Please take your time, and feel free to ask @hi-unc1e for support in the thread 👍

tianshiyeben commented 2 years ago

ok ok tks @hi-unc1e

tianshiyeben commented 2 years ago

Thank you very much for your suggestions. I already know how to fix it and have started to make some updates