Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Outdated security advisory flow #8

Closed
mratsim opened this issue Dec 18, 2023 · 1 comment
Closed

Outdated security advisory flow #8

mratsim opened this issue Dec 18, 2023 · 1 comment
Assignees
Labels
documentation Improvements or additions to documentation

Comments

@mratsim
Copy link

mratsim commented Dec 18, 2023

The suggested security advisory flow is incorrect, probably refering to an old workflow.

If you believe to have found a vulnerability in sha3-d, I strongly advise you
to draft a new security advisory under Security > Securitiy advisories.

In the current Github, only admins can create a security advisory so people have to contact you privately:

https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/creating-a-repository-security-advisory

Who can use this feature

Anyone with admin permissions to a repository, or with a security manager role within the repository, can create a security advisory.

Note: I don't have any security issue to report. Was just curious.

@dd86k
Copy link
Owner

dd86k commented Dec 18, 2023

Hey, thanks for noticing.

I've enabled Private vulnerability reporting (Beta), which "Allow your community to privately report potential security vulnerabilities to maintainers and repository owners.". Hoping this will work.

I've also noticed a typo in the snippet that you highlighted (regarding "Securitiy"), I'll tweak the SECURITY.md file later and apply it to my blake2 repo as well.

@dd86k dd86k self-assigned this Dec 18, 2023
@dd86k dd86k added the documentation Improvements or additions to documentation label Dec 18, 2023
@dd86k dd86k closed this as completed in cec034a Dec 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants