Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add form to submit private vulnerability reports #1374

Closed
Umang01-hash opened this issue Jan 8, 2025 · 1 comment
Closed

Add form to submit private vulnerability reports #1374

Umang01-hash opened this issue Jan 8, 2025 · 1 comment
Assignees
Labels
security Report any vulnerability

Comments

@Umang01-hash
Copy link
Member

Umang01-hash commented Jan 8, 2025

Is your feature request related to a problem? Please describe.
Screenshot 2025-01-08 at 12 20 24 PM

When going through the Best Practices followed for OpenSource Projects on : https://www.bestpractices.dev/en/projects/8099

I found this .

If private vulnerability reports are supported, the project MUST include how to send the information in a way that is kept private. (URL required)

Examples include a private defect report submitted on the web using HTTPS (TLS) or an email encrypted using OpenPGP. If vulnerability reports are always public (so there are never private vulnerability reports), choose "not applicable" (N/A).

Describe the solution you'd like
Private Defect Report via Web:

Provide a URL for submitting vulnerability reports via a secure web form. Create a secure web form for submitting vulnerability reports using HTTPS.

@Umang01-hash
Copy link
Member Author

Closing due to this #1372 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Report any vulnerability
Projects
None yet
Development

No branches or pull requests

1 participant