yaml / pyyaml

Canonical source repository for PyYAML
MIT License
2.54k stars 515 forks source link

Publishing possible security issues #805

Open fuzzah opened 4 months ago

fuzzah commented 4 months ago

Greetings! I have previously reported some issues which might be security-related (sent them to the e-mail mentioned in the security policy), but still no reply.

The message was sent on April 9, 2024 from the address v.korolyov@gardatech.ru. Was it overlooked by any chance?

If these issues are not considered security-related, then I'd like to report them here on github if that's okay.

perlpunk commented 4 months ago

Hi, I've just enabled private vulnerability reporting for this repo: https://github.com/yaml/pyyaml/security Please report anything security related there, thanks. I think I am on the recipients list for the security policy email address but I didn't receive anything.

fuzzah commented 3 months ago

@perlpunk , thank you! It's been almost 2 weeks since I reported it as a GHSA. Now may I kindly ask for someone on the PyYAML team to actually review it? 😿