You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
To improve this next time you could add a SECURITY.md file at the root (what we call a Security Policy). It will provide information to security researchers and developers such as:
how to contact the maintainers (or the team in charge of security)
This would be a welcome addition. Enterprise application run security checks and this particular vulnerability is a blocker for using many other packages.
Hello 👋
I have noticed that some security issues has been reported using public issue like:
To improve this next time you could add a SECURITY.md file at the root (what we call a Security Policy). It will provide information to security researchers and developers such as:
In my projects I use the newest Github feature to report private vulnerability. Example of my file here.
To enable it just go to
Settings
and enablePrivate vulnerability reporting
.I wrote an article that explains how to securize a project or orgization on GitHub in hope to help fellow maintainers: https://dev.to/nodesecure/securize-your-github-org-4lb7
If you need any help do not hesitate
Best regards,
Thomas
The text was updated successfully, but these errors were encountered: