Large-scale disclosure guidelines
See original GitHub issueHello! My name is Isaac and I work with a small group called R2C. We’re writing JavaScript analysis tools and one of our projects is inspired by @ChALkeR’s work to find new Buffer()
vulnerabilities. Our analyzer is context-aware and has found more undisclosed vulnerabilities lurking in the long-tail of npm packages. I’m reaching out to get the NSWG’s thoughts and help after talking with @vdeturckheim and @reedloden earlier this month.
- Despite new
Buffer()
being deprecated in newer versions of Node (since 2016), is it still something the NSWG wants disclosed? - If there are a large number of disclosures, what are the best practices for disclosure through NSWG?
- Have large scale disclosures been done before that we can learn from?
- Do you have recommendations for people or other communities that might be interested helping us triage our findings and disclose to NSWG? We may be interested in sponsoring work or supporting bounties.
@vdeturckheim suggested we might chat about this at the next working group meeting. Looking forward to your thoughts!
Issue Analytics
- State:
- Created 4 years ago
- Comments:8 (6 by maintainers)
Top Results From Across the Web
INDUSTRY GUIDES | SEC.gov
Statistical Disclosure by Bank Holding Companies. General Instructions. Guide 3. 1. This Guide applies to the description of business portions of those bank ......
Read more >TILA-RESPA Integrated Disclosure: Guide to the Loan ...
For more than 30 years, Federal law required lenders to provide two different disclosure forms to consumers applying for a mortgage.
Read more >Disclosure Manual: Chapter 29 - Large Scale Case ...
Introduction. Large-scale cases create difficulties for the prosecutor in terms of the volume of both the evidence and unused material.
Read more >The Enhancement and Standardization of Climate-Related ...
Exempt EGCs From Scope 3 Emissions Disclosure Requirements ... perform large-scale analysis and comparison of climate-related disclosures ...
Read more >Publication 1075 - Tax Information Security Guidelines - IRS
2.E Reporting Requirements – IRC § 6103(p)(4)(E) ... mission/business requirements. Because of the challenges of implementing this control on large scale,.
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
@sam-github We haven’t had as much time to work on this recently, but we are still interested and I was just talking about it to @ChALkeR a few hours ago. There was some confusion and I missed the NSWG meeting where it was discussed, but I would be interested in discussing it more broadly!
To answer your question and @lirantal (sorry for delay! my github notifications are very overwhelmed):
allocUnsafe
API). We look for instances where the Buffer API is definitely used with a number or with a value that could be a number or of some other type.👋@ievans wonderful to hear about this initiative
My input:
Happy you’re bringing this up, let’s chat indeed in the next agenda call! 😃