vibe-d / vibe.d

Official vibe.d development
MIT License
1.15k stars 284 forks source link

SECURITY #2701

Open myOmikron opened 1 year ago

myOmikron commented 1 year ago

I couldn't find any information regarding handling of incidents / security problems on this repository. As this is IMHO quite important for a web-framework it would be nice to have some sort of contact information (email + pgp preferred over proprietary chats) and information about how to proceed further, what steps are executed and how quickly responses can be expected.

Some proposals:

WebFreak001 commented 1 year ago

There hasn't been any response from vibe.d maintainers yet, but if you have something to report, you can probably send a mail to the dlang security team (see https://dlang.org/security.html), they are most likely to get in touch with the vibe.d maintainers and get fixes in.