Hi, I found an important security problem in goutil, how can I get in touch with you in a private way and submit my security report?
Yes, I do would like to submit a PR to help you fix it. But directly PR may disclose the detail of the vulnerability too early and lead to some exploits by others. So in regular progress, as a security researcher, I need a safe way to submit my report to you, the matainer, and prove the danger of the vulnerability first. Both email or qq will be ok.
Github also suggests this, too. More information can be found in https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository
OK, thanks. My email is [email protected]
@inhere Hi , would you like to publish a security advisory for this vulnerability?
@inhere Hi, Can you see New draft security advisory
in https://github.com/gookit/goutil/security/advisories? Click the button and you can create new security advisory. If you feel confused about some blanks, you can invite me as a collaborator to edit it.
@inhere Maybe you can take this one as a reference, a security advisory published by another famous golang tool library, lancet: GHSA-pp3f-xrw5-q5j4
@cokeBeer please see GHSA-fx2v-qfhr-4chv
@inhere Hi, I have finished the security advisory content. Could you request a CVE identification number in that page before publish it ? (Only maintainers can do so)
Owner Name | gookit |
Repo Name | goutil |
Full Name | gookit/goutil |
Language | Go |
Created Date | 2018-07-03 |
Updated Date | 2023-03-22 |
Star Count | 1263 |
Watcher Count | 29 |
Fork Count | 142 |
Issue Count | 3 |