Skip to content

Add SECURITY.md #309

Closed
Closed
@JamieSlome

Description

@JamieSlome

Hey there!

I belong to an open source security research community, and a member (@ranjit-git) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

Activity

andrewicarlson

andrewicarlson commented on Apr 4, 2022

@andrewicarlson
Contributor

Hey @JamieSlome, thanks for bringing this up. I've issued a PR adding a SECURITY.md but in the meantime please email security@prisma.io

added a commit that references this issue on Apr 4, 2022
JamieSlome

JamieSlome commented on Apr 4, 2022

@JamieSlome
Author

@andrewicarlson - thanks for the support here 👍

We e-mailed the organisation e-mail a little while back but will send the details to the new e-mail address now. Just for reference, you can find the report directly here:

https://huntr.dev/bounties/d6418ac2-fce8-4963-b6e5-9b0025238451/

It is private and only accessible to maintainers with repository write permissions.

janpio

janpio commented on Apr 4, 2022

@janpio

Hey @JamieSlome, trying to follow up on how we missed this before. What organisation e-mail was that?

image

How was that contact made?
JamieSlome

JamieSlome commented on Apr 4, 2022

@JamieSlome
Author

@janpio - it was labs@prisma.io.

The e-mail would have been from security@huntr.dev 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

      Development

      Participants

      @janpio@andrewicarlson@JamieSlome

      Issue actions

        Add SECURITY.md · Issue #309 · graffle-js/graffle