Skip to content

Update security reporting instructions in SECURITY.md - #11

Open
danielpeintner wants to merge 1 commit into
mainfrom
danielpeintner-patch-1-1
Open

Update security reporting instructions in SECURITY.md#11
danielpeintner wants to merge 1 commit into
mainfrom
danielpeintner-patch-1-1

Conversation

@danielpeintner

Copy link
Copy Markdown
Member

Use the new Eclipse template from https://github.com/eclipse-csi/security-handbook/blob/main/templates/SECURITY.md

Changes I made to the template

  • Updates the GITHUB ADVISORIES link to https://github.com/eclipse-thingweb/node-wot/security/advisories/new
    • The template allows removing this possibility. Shall we remove it or keep it?
    • If we keep it, we can no longer copy and paste it everywhere since the link changes
    • If we remove it, we might want to adapt the text "report it using one of the following ways" since there is only one way left
  • Removed the last part about "versions," which seems neither clear nor necessary to me (wasn't there bewfore either).
  • Question: The template talks about "SQL injection" which will hardly happen in our case. Shall we remove it as well? Was there before also.

Use the new Eclipse template from https://github.com/eclipse-csi/security-handbook/blob/main/templates/SECURITY.md

Changes I made to the template
* Updates the GITHUB ADVISORIES link to https://github.com/eclipse-thingweb/node-wot/security/advisories/new
  * The template allows removing this possibility. Shall we do that or keep it?
  * If we keep it, we can no longer copy and paste it everywhere since the link changes
* Removed the last part about "versions," which seems neither clear nor necessary to me.
* Question: The template talks about "SQL injection" which will hardly happen in our case. Shall we remove it as well?

@egekorkan egekorkan left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@danielpeintner thanks :)

Question: The template talks about "SQL injection" which will hardly happen in our case. Shall we remove it as well? Was there before also.

I would keep it as it is just an example

However, I think that we should NOT merge this PR and create a security.md in all repos due to that link. A bit annoying :)

The template allows removing this possibility. Shall we remove it or keep it?

I am not sure if this is explicit. The user has multiple choices, we should provide both.

@danielpeintner

Copy link
Copy Markdown
Member Author

However, I think that we should NOT merge this PR and create a security.md in all repos due to that link. A bit annoying :)

We can create a PR for each repo but we should decide what to do with this repo

Shall we change the line to something like the following mention "sub-project" ? Otherwise we should delete the file here.

Report a [vulnerability](https://github.com/eclipse-thingweb/<sub-project>/security/advisories/new) directly via private vulnerability reporting on GitHub

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants