Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability disclosure research #89

Closed
rarkins opened this issue Dec 23, 2020 · 5 comments
Closed

Vulnerability disclosure research #89

rarkins opened this issue Dec 23, 2020 · 5 comments

Comments

@rarkins
Copy link
Contributor

rarkins commented Dec 23, 2020

Is this WG involved in any way in this upcoming vulnerability disclosure survey by GitHub?

image

@rarkins
Copy link
Contributor Author

rarkins commented Dec 23, 2020

Tweet for context:

image

@Foxboron
Copy link
Contributor

Nothing in the meetings at least.

@MarcinHoppe
Copy link
Contributor

Not to my knowledge. I will reach out to Hauwa to check if there is any overlap.

@HonkingGoose
Copy link

I think I found something relevant in #99 (comment), full quote:

The group would like to develop a CVD guide for OSS projects. The guide should include the CVD process, how to work with security researchers in a CVD setting, and templates for security policies (issue #95).

A fork of Google's CVD for OSS guide has been added here to give a starting base. Please open issues, PRs, and edit away!

The linked ossf/oss-vulnerability-guide repository has a section on Feedback:

Feedback

We welcome feedback from OSS project maintainers and security researchers on this guide. Opening a GitHub Issue is the best way to send feedback (see CONTRIBUTING.md for directions on submitting PRs).

So I think this is where you can contribute as a maintainer or security researcher.

I might be totally wrong though... 🙈 Just wanted to mention what I found, in case it's relevant.

@rarkins
Copy link
Contributor Author

rarkins commented Mar 9, 2022

I think we can close this issue now. The answer appears to be that it was private research which GitHub performed for commercial purposes, not OSSF.

@rarkins rarkins closed this as completed Mar 9, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants