Disclosure of reported extension vulnerabilities and public key for signing vulnerability reports? #1688
studyingegret
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm recently concerned with the vulnerability of an extension. I'd like to know if there are plans to disclose the vulnerability if I report it as a concern to the Marketplace.
Also I'm interested in a public key to encrypt vulnerability reports, if there is one.
(As for current plans, I've sent them an email according to their security policy and am waiting for their response, and I plan to report only if the extension developers will not fix it or a fix is not done in 90 days.)
Beta Was this translation helpful? Give feedback.
All reactions