-
-
Notifications
You must be signed in to change notification settings - Fork 156
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
make sure that privately reported issues do not show up in the public image folder - create a new bucket and use that for private issues #1685
Comments
/assign |
it would be really helpful if you could provide a link. |
fixed #1691 |
I think the best way to do this would be to create a new private bucket |
@DonnieBLT what does exactly new private bucket means ? |
A private bucket, in the context of cloud computing and storage, typically refers to a storage container within a cloud storage service that is designed to hold data. Unlike public buckets, which can be accessed by anyone with the right URL, private buckets are restricted and can only be accessed by specific, authorized users or systems. Key features of a private bucket include:
Private buckets are commonly used by businesses and individuals to store sensitive data like personal information, confidential business documents, or proprietary data, ensuring that it's not publicly accessible or vulnerable to unauthorized access. |
@DonnieBLT I think this issue can be closed, since #1691 is merged |
No, this issue is still valid - we'll have a separate private bucket for private issues |
for this issue if the issue is private use the PRIVATE_BUCKET_ID (code this in and we can change it when we deploy) |
⏰ This issue has been automatically unassigned due to 24 hours of inactivity. |
2 similar comments
⏰ This issue has been automatically unassigned due to 24 hours of inactivity. |
⏰ This issue has been automatically unassigned due to 24 hours of inactivity. |
we'll have a separate private bucket for private issues
Private Bug Bounties with Paid Incentives and Confidentiality.
A feature that allows companies to conduct private, paid bug bounties in a non-commercial way would enable companies to crowdsource security testing for their software systems while maintaining a high level of confidentiality. This feature would involve creating a closed bug bounty program that is accessible only to a select group of researchers who have been vetted by the company. The bounty program could be offered as a paid incentive to researchers who discover and report critical bugs in the company's software.
Here's how this feature might work:
This feature would allow companies to conduct private, paid bug bounties without the need for a commercial marketplace or public disclosure of vulnerabilities. It would help companies to identify and fix security vulnerabilities in their software systems more quickly and efficiently, while also building a relationship
The text was updated successfully, but these errors were encountered: