git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Where to report security vulnerabilities in git?

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 22, 2015, 00:16 UTC
Message-ID
<CAPc5daUYCyJFr_4-u60QGZavxEM=TZSWq_6O7C4E5kuG+gPy7w@mail.gmail.com>
In-Reply-To
<CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>
On Fri, Aug 21, 2015 at 3:55 PM, Guido Vranken <guidovranken@gmail.com> wrote:
Show 5 quoted lines
> germane exploitation details. I did find an older thread in the
> archive addressing this question (
> http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
> because I'm unsure if those e-mail addresses are still relevant, I'm
> asking again.

Indeed that was an old advice. Recent releases of "A note from the maintainer" has this paragraph:

If you think you found a security-sensitive issue and want to disclose it to us without announcing it to wider public, please contact us at our security mailing list <git-security@googlegroups.com>.

Previous: Stefan BellerNext: Sitaram Chamarty
Message 3 of 4 in “Where to report security vulnerabilities in git?”
  1. Guido VrankenAug 21, 2015
  2. Stefan BellerAug 22, 2015
  3. Junio C HamanoAug 22, 2015
  4. Sitaram ChamartyAug 24, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.