cloud-gov / cg-site

The cloud.gov website

Home Page:https://cloud.gov

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Reporting a vulnerability

igibek opened this issue · comments

Hello!

I hope you are doing well!

We are a security research team. Our tool automatically detected a vulnerability in this repository. We want to disclose it responsibly. GitHub has a feature called Private vulnerability reporting, which enables security research to privately disclose a vulnerability. Unfortunately, it is not enabled for this repository.

Can you enable it, so that we can report it?

Thanks in advance!

PS: you can read about how to enable private vulnerability reporting here: https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

Hi @igibek, thank you for reaching out. You can find details of our vulnerability disclosure process here: https://cloud.gov/docs/ops/security-ir/#purpose

If you have a vulnerability to disclose, please reach out through those channels. In the meantime, I'm going to close this issue. Thank you.