PythonBuddy icon indicating copy to clipboard operation
PythonBuddy copied to clipboard

Who to contact for security issues

Open benharvie opened this issue 3 years ago • 3 comments

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@evanottinger) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

benharvie avatar Oct 29 '22 16:10 benharvie

sure - feel free to shoot me an email at [email protected]

I published this back in 2016 so haven't been too active maintaining it but happy to hear any feedback.

ethanchewy avatar Dec 11 '22 04:12 ethanchewy

Ålso feel free to open a PR with the security fix you have in mind. In the readme, I do mention alternatives that users can use to better secure their own version of PythonBuddy.

ethanchewy avatar Dec 11 '22 04:12 ethanchewy

I couldn't open the link that you sent via email. It times out when I copy and paste it in incognito.

ethanchewy avatar Dec 11 '22 16:12 ethanchewy