Code Monkey home page Code Monkey logo

Comments (3)

JamieSlome avatar JamieSlome commented on June 24, 2024 1

@gruns - thanks for all of your feedback on the above.

  1. We receive a lot of vulnerability reports, especially against very large projects, and so don't assume that reports should be public by default. We had tried this in the past and got a fair amount of bite back, and so do everything via responsible disclosure now. That said, if a maintainer is happy for a report to be made public, we will always support that :) You can see the report here, which I have now made public for you.
  2. In all of the cases listed above, and for all of our outreach, we first request an e-mail address in the SECURITY.md, so that maintainers can select an e-mail address where they want reports to go, plus we can authorize the address that's been created by a permitted maintainer. Until we have that e-mail address, we don't disclose it.
  3. By no means are we trying to promote the platform, rather just share the contents of reports, responsibly whilst trying not to share our brand as much as possible. Previously, we included our report URLs directly in these issues, but this also had problems, as this specifically looked like a scheme to promote the company. Hence, we wait for the e-mail address to share the report content.

Also:

Screenshot 2022-07-06 at 09 58 42

And feel free to check out the thousand of vulnerabilities found previously by our researchers:

https://huntr.dev/bounties/hacktivity

from furl.

gruns avatar gruns commented on June 24, 2024

is this potential issue too sensitive to just create a (public) issue here in this repo?

also you create a ton of issues exactly like this, without disclosing any security vulnerabilities

is this just a scheme to promote your company, huntr helper? 😉

from furl.

gruns avatar gruns commented on June 24, 2024

fwiw, no results for furl when searching on huntr.dev:

image

from furl.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.