Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Great work but is it contributed back to the vendors? #1

Closed
benedekh opened this issue Feb 13, 2024 · 1 comment
Closed

Great work but is it contributed back to the vendors? #1

benedekh opened this issue Feb 13, 2024 · 1 comment

Comments

@benedekh
Copy link

Hi Team,

Thanks for the great work you are doing by patching the (security) vulnerabilities in the open-source projects! 馃帀馃憦馃檹

One quick question: do you contribute these patches back to the vendors or just collect it here?

I've seen that in case of the ip npm package you proposed your fixes in a comment of a pull request that fixes the same problem in a different way.

However, in case of jackson-databind, I have not seen your proposed fixes in their repository. (Maybe I've missed the PR.)

I think, it would be a huge loss if your patches would be just laying around here without being contributed to the vendors, thereby helping their efforts of closing security loopholes and making the software ecosystem more secure and reliable.

@itamarsher
Copy link

itamarsher commented Feb 13, 2024

Hi @benedekh
Thank you for your kind words!
Due to the number of patches we produce + maintainers generally not accepting PRs for unmaintained branches (just an example: mde/ejs#580) - we decided to leave that effort up to the community/maintainers.

If you wish to pull the built artifacts directly, our artifact server is free for open source projects/individuals, and you can automatically apply the patches using the CLI https://github.com/seal-community/cli.

@itamarsher itamarsher closed this as not planned Won't fix, can't repro, duplicate, stale Feb 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants