Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a security policy #3015

Open
ghost opened this issue Dec 20, 2021 · 3 comments
Open

Add a security policy #3015

ghost opened this issue Dec 20, 2021 · 3 comments
Labels
security Pull requests that address a security vulnerability

Comments

@ghost
Copy link

ghost commented Dec 20, 2021

This would go along with #365's 3rd task as we would need a contact email for security:
change contact address to something under the up-for-grabs.net domain

It can be helpful to let people report security vulnerabilities to this repo - although I don't know how likely a security vulnerability is given that this is mostly a static site.

@shiftkey shiftkey added the security Pull requests that address a security vulnerability label Dec 20, 2021
@jalaniz1
Copy link
Contributor

jalaniz1 commented Jul 2, 2022

Hmm, I think a potential source of vulnerabilities could come from the dependencies? Github has a dependabot security feature that can be enabled to detect dependencies that have security vulnerabilities and can automatically open a PR to resolve the issue by updating the tags.

I did a scan with Lighthouse on up for grabs .net and it did find this:
image

@ritwik12
Copy link
Collaborator

ritwik12 commented Jul 3, 2022

@jalaniz1 Thanks for checking on this. Can you please open up a PR for this?

@jalaniz1
Copy link
Contributor

jalaniz1 commented Jul 6, 2022

@ritwik12 Here it is #3263

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Pull requests that address a security vulnerability
Projects
None yet
Development

No branches or pull requests

3 participants