Re: Where to report security vulnerabilities in git?
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Aug 22, 2015, 00:16 UTC
- Message-ID
- <CAPc5daUYCyJFr_4-u60QGZavxEM=TZSWq_6O7C4E5kuG+gPy7w@mail.gmail.com>
- In-Reply-To
- <CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>
On Fri, Aug 21, 2015 at 3:55 PM, Guido Vranken <guidovranken@gmail.com> wrote:
Show 5 quoted lines
> germane exploitation details. I did find an older thread in the > archive addressing this question ( > http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but > because I'm unsure if those e-mail addresses are still relevant, I'm > asking again.
Indeed that was an old advice. Recent releases of "A note from the maintainer" has this paragraph:
If you think you found a security-sensitive issue and want to disclose it to us without announcing it to wider public, please contact us at our security mailing list <git-security@googlegroups.com>.