-
Notifications
You must be signed in to change notification settings - Fork 45
Create security.md #253
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Create security.md #253
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||
|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,33 @@ | ||||||||
| ### Security Vulnerability Reporting | ||||||||
| The Product Security Incident Response Team (PSIRT) at Solid acknowledges the valuable role researchers play. We encourage reporting of any concerns and vulnerabilities found in our sites or software. | ||||||||
|
|
||||||||
| [email protected] | ||||||||
| Submit an issue to our team on github | ||||||||
|
||||||||
| [email protected] | |
| Submit an issue to our team on github | |
| Please submit any issues to [our team on github](needs_the_repo/issues/), or email <[email protected]>. |
timea-solid marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
timea-solid marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Software often contains third party or open source libraries and binaries. Prior to submitting a request to validate how a security issue in third party components may impact Solid, please review the section on Handling Third Party CVE (Common Vulnerabilities and Exposures).
timea-solid marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
To be clear, at loss of a better solution, are you recommended that the list of Security Advisories related to Solid will be currated manually as a list:
- inside this present document; or;
- in an external
security-advisories.md?
I would probably have a slight preference for the latter.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Notifications and descriptions of security incidents are available here. | |
| Notifications and descriptions of security incidents are available [here](needs_a_link_to_document_or_directory). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inrupt.com? Or solidproject.org? This document is starting to exhibit a split personality...
Uh oh!
There was an error while loading. Please reload this page.