Closed
Description
Hey there!
I belong to an open source security research community, and a member (@ranjit-git) has found an issue, but doesn’t know the best way to disclose it.
If not a hassle, might you kindly add a SECURITY.md
file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.
Thank you for your consideration, and I look forward to hearing from you!
(cc @huntr-helper)
Metadata
Metadata
Assignees
Labels
No labels
Activity
Added a SECURITY.md per graffle-js#309
andrewicarlson commentedon Apr 4, 2022
Hey @JamieSlome, thanks for bringing this up. I've issued a PR adding a
SECURITY.md
but in the meantime please email security@prisma.iochore: added a SECURITY.md per #309 (#336)
JamieSlome commentedon Apr 4, 2022
@andrewicarlson - thanks for the support here 👍
We e-mailed the organisation e-mail a little while back but will send the details to the new e-mail address now. Just for reference, you can find the report directly here:
https://huntr.dev/bounties/d6418ac2-fce8-4963-b6e5-9b0025238451/
It is private and only accessible to maintainers with repository write permissions.
janpio commentedon Apr 4, 2022
Hey @JamieSlome, trying to follow up on how we missed this before. What organisation e-mail was that?

How was that contact made?JamieSlome commentedon Apr 4, 2022
@janpio - it was
labs@prisma.io
.The e-mail would have been from
security@huntr.dev
👍