trinodb / trino

Official repository of Trino, the distributed SQL query engine for big data, formerly known as PrestoSQL (https://trino.io)
https://trino.io
Apache License 2.0
9.83k stars 2.85k forks source link

Improve vulnerability reporting process #22231

Open Marcono1234 opened 3 weeks ago

Marcono1234 commented 3 weeks ago

As part of reporting https://github.com/airlift/aircompressor/security/advisories/GHSA-973x-65j7-xcf4 for Aircompressor, I also tried to contact the maintainers here, and there were several problems:

Suggestions

mosabua commented 3 weeks ago

I am going to take this on @martint since I was already looking towards getting some openssf badges and such. Will work with you and @wendigo and others.