question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Hey there!

I belong to an open source security research community, and a member (@ktg9) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

Issue Analytics

  • State:closed
  • Created 2 years ago
  • Comments:6 (2 by maintainers)

github_iconTop GitHub Comments

1reaction
JamieSlomecommented, Dec 3, 2021

@solarissmoke - just for reference, you can find the report here: https://huntr.dev/bounties/c6ed0ec6-bcad-41a4-8f9a-5b0db7859db6/

It is only visible to permissive maintainers 👍

0reactions
joeyjurjenscommented, Oct 20, 2022

Closing this issue because there wasn’t really a vulnerability risk.

Read more comments on GitHub >

github_iconTop Results From Across the Web

Securing your repository
From the main page of your repository, click Security. Click Security policy. Click Start setup. Add information about supported versions of your project...
Read more >
Add a SECURITY.md file to your Azure Repos
Likewise, it's becoming increasingly common to add a SECURITY.md file that highlights security-related information for your project.
Read more >
Security policy | GitHub Changelog
Repositories may now specify a security policy by creating a file named SECURITY.MD. This file should be used to instruct users about how ......
Read more >
Add a SECURITY.md explaining how to report ...
This file can explain the procedures we have security.drupal.org, how to report a Drupal core vulnerability, how it works for core, security ......
Read more >
10 GitHub Security Best Practices - PurpleBox Inc.
1. Never store credentials in GitHub · 2. Always use MFA · 3. Create a SECURITY.md file · 4. Disable forking · 5....
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found