PowerShellGallery
PowerShellGallery copied to clipboard
Email is revealed in "Package published" notification
Prerequisites
- [X] Write a descriptive title.
- [X] Make sure you are able to repro it on the latest version
- [X] Search the existing issues.
Steps to reproduce
- Be owner of a module/package
- (Maybe, see actual behavior comment) Enable notification setting shown below
- Co-owner publishes a new version.
Expected behavior
Email remains private. The note says "Also, we never reveal your email address to other users.", not excluding co-owners. Use individual notification emails or BCC
Actual behavior
Email with subject "[PowerShell Gallery] Package published - <modulename> <version>" adds all owners in To-field exposing the email.
Bonus bug? Package was published with another account, yet I got an email. Is this expected? Option only to exclude self published packages?
Error details
No response
Environment data
N/A
Version
N/A
Visuals
No response
Combined with https://github.com/PowerShell/PowerShellGallery/issues/265 this isn't great from a privacy standpoint as I'm also unable to update my account email.