Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a security policy(SECURITY.md) #5306

Open
Alexia opened this issue Feb 19, 2021 · 2 comments
Open

Create a security policy(SECURITY.md) #5306

Alexia opened this issue Feb 19, 2021 · 2 comments
Assignees

Comments

@Alexia
Copy link

Alexia commented Feb 19, 2021

This organization could use a security policy visible in the file root for reporting vulnerabilities on beta.gouv.fr and the Github organization.

This morning @Morendil invited me to the Github organization and granted me access to the beta.gouv.fr team. This immediately granted me access read and write to the team's repositories. This also gave me administrator access to https://beta.gouv.fr/admin/ and https://blog.beta.gouv.fr/admin/.

As far as I can tell my profile was not inspected to determine if I was the correct person that Morendil was attempting to invite.

@Morendil
Copy link
Contributor

Morendil commented Feb 19, 2021

Hi @Alexia - thanks for the feedback. We are currently in the process of setting up a bug bounty (to launch in the next few days) and publishing a vulnerability disclosure policy (no schedule yet), which might well take the form of such a file.

Would you please contact me privately at the email address listed on my profile to review the events you mention above ?

@Morendil
Copy link
Contributor

We have corrected the error and reconstituted the events leading up to it, and I'm confident your prompt notification will help in making the process more robust. Thanks again! It was a pleasure having you in the org, however briefly or erroneously.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants