Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create SECURITY.md #886

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

Create SECURITY.md #886

wants to merge 1 commit into from

Conversation

gogo2464
Copy link

I am not responsible of the disclosure department. Could you choose the condition (avoiding to attack the infra or not?, how to reward if reward?, etc...).

I am not responsible of the disclosure department. Could you choose the condition (avoiding to attack the infra or not?, how to reward if reward?, etc...).
Copy link

cla-bot bot commented Jan 10, 2025

We require contributors to sign our Contributor License Agreement (CLA), and we don't have yours on file. In order for us to review and merge your code, please sign CLA to get yourself added.

Sourcegraph teammates:

@jtibshirani
Copy link
Member

Thanks for the suggestion @gogo2464, I'm asking around internally for some guidance on this.

Comment on lines +1 to +9
# Security Policy

## Supported Versions

Any impacted version are intersting to know and to report vulnerabilities.

## Reporting a Vulnerability

In case you found a vulnerability in source graph, you could report a private vulnerability disclosure to [email protected].
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This what our policy typically would look like:

Suggested change
# Security Policy
## Supported Versions
Any impacted version are intersting to know and to report vulnerabilities.
## Reporting a Vulnerability
In case you found a vulnerability in source graph, you could report a private vulnerability disclosure to [email protected].
# Security Policy
Our security policy is documented at https://sourcegraph.com/security.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can provide the link. I want to ensure that, in practice, a cyber security researcher could send a private email to someone in the team to fix the vulnerability.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you follow the link, there's a bug bounty instruction that asks for emailing to [email protected].

@evict
Copy link
Contributor

evict commented Jan 27, 2025

Thank you for helping us out here. If you address these changes I am happy to merge!

@gogo2464
Copy link
Author

The point is if somebody finds a software vulnerability, he could report to a private person.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants