Skip to content

Security vulnerability + preferred disclosure channel #169

Description

@obi1kenobi

I discovered a serious security vulnerability in the client, and in the spirit of responsible disclosure, I was hoping to discuss it privately with the maintainers of this project. However, I was not able to find a contact email address of any kind for either @mogui or @Ostico , and I'm unaware of any other maintainers with admin access to the repo.

I didn't want to simply open a pull request with the fix, because that until that pull request is merged and a new version is put on pypi, it's just sitting there as a proof-of-concept exploit of a vulnerability.

I would appreciate it if one of the maintainers could reply to this issue and direct me to the preferred channel for disclosing security vulnerabilities.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions