git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Where to report security vulnerabilities in git?

From
Stefan Beller <sbeller@google.com>
Date
Aug 22, 2015, 00:02 UTC
Message-ID
<CAGZ79kZdkcZQKxZ+M8WoXDZ6J=nk7C1E-JTBEcYYwTB_kORNjQ@mail.gmail.com>
In-Reply-To
<CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>

The addresses are still valid. (I think there was a plan to introduce a git-security@... but I am not sure if that happened.)

> Current practice is to contact Junio C Hamano <gitster <at> pobox.com>.
> Cc-ing Jeff King <peff <at> peff.net> isn't a bad idea while at it.
Just go for that.
On Fri, Aug 21, 2015 at 3:55 PM, Guido Vranken <guidovranken@gmail.com> wrote:
Show 19 quoted lines
> List,
>
> I would like to report security vulnerabilities in git. Due to the
> sensitive nature of security-impacting bugs I would like to know if
> there's a dedicated e-mail address for this, so that the issues at
> play can be patched prior to a coordinated public disclosure of the
> germane exploitation details. I did find an older thread in the
> archive addressing this question (
> http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
> because I'm unsure if those e-mail addresses are still relevant, I'm
> asking again.
>
> Thanks.
>
> Guido
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous: Guido VrankenNext: Junio C Hamano
Message 2 of 4 in “Where to report security vulnerabilities in git?”
  1. Guido VrankenAug 21, 2015
  2. Stefan BellerAug 22, 2015
  3. Junio C HamanoAug 22, 2015
  4. Sitaram ChamartyAug 24, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.