Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a Security Policy #3106

Closed
eslerm opened this issue Dec 5, 2023 · 4 comments · Fixed by #3113
Closed

Create a Security Policy #3106

eslerm opened this issue Dec 5, 2023 · 4 comments · Fixed by #3113

Comments

@eslerm
Copy link

eslerm commented Dec 5, 2023

gunicorn lacks a SECURITY.md

Recent security sensitive bugs have been reported privately, not been addressed, and then reported publicly #3091. That reporter is disclosing security reports publicly now #3104.

By defining a Security Policy, gunicorn can set clear expectations to reporters who want to keep gunicorn and users safe. Here's GitHub Security's policy as an example.

Another option is to use GitHub's private vulnerability reporting feature: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

@benoitc
Copy link
Owner

benoitc commented Dec 6, 2023 via email

@juhoinkinen
Copy link

I think it would not hurt to have a SECURITY.md in addition to the GitHub's Vulnerability reporting feature; in SECURITY.md there could be an instruction to use the feature (which I think is a new one, currently with beta status? And it is perhaps not as easily findable as the SECURITY.md file).

The SECURITY.md could have also other security related info, like how-to-use-gunicorn-securely, see e.g. https://github.com/tensorflow/tensorflow/security.

@eslerm
Copy link
Author

eslerm commented Dec 25, 2023

Thank you for working on this 🙏

Please note that the Report a vulnerability button is not yet available as stated in the SECURITY.md (see this guide for configuration).

@eslerm
Copy link
Author

eslerm commented Jan 26, 2024

@benoitc could this issue be re-opened until the current SECURITY.md is implemented?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants