git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Where to report security vulnerabilities in git?

From
Sitaram Chamarty <sitaramc@gmail.com>
Date
Aug 24, 2015, 04:13 UTC
Message-ID
<55DA99E2.7090707@gmail.com>
In-Reply-To
<CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>
On 08/22/2015 04:25 AM, Guido Vranken wrote:
Show 11 quoted lines
> List,
> 
> I would like to report security vulnerabilities in git. Due to the
> sensitive nature of security-impacting bugs I would like to know if
> there's a dedicated e-mail address for this, so that the issues at
> play can be patched prior to a coordinated public disclosure of the
> germane exploitation details. I did find an older thread in the
> archive addressing this question (
> http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
> because I'm unsure if those e-mail addresses are still relevant, I'm
> asking again.

If it has anything to do with remote access (via ssh or http) please copy me also. I wrote/write/maintain gitolite, which is a reasonably successful access control system for git servers.

regards sitaram

Previous: Junio C Hamano
Message 4 of 4 in “Where to report security vulnerabilities in git?”
  1. Guido VrankenAug 21, 2015
  2. Stefan BellerAug 22, 2015
  3. Junio C HamanoAug 22, 2015
  4. Sitaram ChamartyAug 24, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.