# Where to report security vulnerabilities in git?

4 messages from 2015-08-21 to 2015-08-24. Participants: Guido Vranken, Stefan Beller, Junio C Hamano, Sitaram Chamarty.
Thread: https://gitlist.dev/t/40153

## Guido Vranken, 2015-08-21 22:55

Subject: Where to report security vulnerabilities in git?
Message-ID: <CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>
URL: https://gitlist.dev/e/CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A%40mail.gmail.com

```
List,

I would like to report security vulnerabilities in git. Due to the
sensitive nature of security-impacting bugs I would like to know if
there's a dedicated e-mail address for this, so that the issues at
play can be patched prior to a coordinated public disclosure of the
germane exploitation details. I did find an older thread in the
archive addressing this question (
http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
because I'm unsure if those e-mail addresses are still relevant, I'm
asking again.

Thanks.

Guido

```

## Stefan Beller, 2015-08-22 00:02

Subject: Re: Where to report security vulnerabilities in git?
Message-ID: <CAGZ79kZdkcZQKxZ+M8WoXDZ6J=nk7C1E-JTBEcYYwTB_kORNjQ@mail.gmail.com>
URL: https://gitlist.dev/e/CAGZ79kZdkcZQKxZ%2BM8WoXDZ6J%3Dnk7C1E-JTBEcYYwTB_kORNjQ%40mail.gmail.com
In-Reply-To: <CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>

```
The addresses are still valid. (I think there was a plan to introduce
a git-security@...
but I am not sure if that happened.)

> Current practice is to contact Junio C Hamano <gitster <at> pobox.com>.
> Cc-ing Jeff King <peff <at> peff.net> isn't a bad idea while at it.

Just go for that.


On Fri, Aug 21, 2015 at 3:55 PM, Guido Vranken <guidovranken@gmail.com> wrote:
> List,
>
> I would like to report security vulnerabilities in git. Due to the
> sensitive nature of security-impacting bugs I would like to know if
> there's a dedicated e-mail address for this, so that the issues at
> play can be patched prior to a coordinated public disclosure of the
> germane exploitation details. I did find an older thread in the
> archive addressing this question (
> http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
> because I'm unsure if those e-mail addresses are still relevant, I'm
> asking again.
>
> Thanks.
>
> Guido
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html

```

## Junio C Hamano, 2015-08-22 00:16

Subject: Re: Where to report security vulnerabilities in git?
Message-ID: <CAPc5daUYCyJFr_4-u60QGZavxEM=TZSWq_6O7C4E5kuG+gPy7w@mail.gmail.com>
URL: https://gitlist.dev/e/CAPc5daUYCyJFr_4-u60QGZavxEM%3DTZSWq_6O7C4E5kuG%2BgPy7w%40mail.gmail.com
In-Reply-To: <CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>

```
On Fri, Aug 21, 2015 at 3:55 PM, Guido Vranken <guidovranken@gmail.com> wrote:
> germane exploitation details. I did find an older thread in the
> archive addressing this question (
> http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
> because I'm unsure if those e-mail addresses are still relevant, I'm
> asking again.

Indeed that was an old advice. Recent releases of "A note from the
maintainer" has this paragraph:

If you think you found a security-sensitive issue and want to disclose
it to us without announcing it to wider public, please contact us at
our security mailing list <git-security@googlegroups.com>.

```

## Sitaram Chamarty, 2015-08-24 04:13

Subject: Re: Where to report security vulnerabilities in git?
Message-ID: <55DA99E2.7090707@gmail.com>
URL: https://gitlist.dev/e/55DA99E2.7090707%40gmail.com
In-Reply-To: <CAO5O-EKaarYDBd-cpVvKVXTWfKm10ttqd3A6wNe2cXGriGux1A@mail.gmail.com>

```
On 08/22/2015 04:25 AM, Guido Vranken wrote:
> List,
> 
> I would like to report security vulnerabilities in git. Due to the
> sensitive nature of security-impacting bugs I would like to know if
> there's a dedicated e-mail address for this, so that the issues at
> play can be patched prior to a coordinated public disclosure of the
> germane exploitation details. I did find an older thread in the
> archive addressing this question (
> http://thread.gmane.org/gmane.comp.version-control.git/260328/ ), but
> because I'm unsure if those e-mail addresses are still relevant, I'm
> asking again.

If it has anything to do with remote access (via ssh or http) please
copy me also.  I wrote/write/maintain gitolite, which is a reasonably
successful access control system for git servers.

regards
sitaram



```
