Closed
Description
Hi!
I was talking on google/oss-fuzz#402 but as description of this repo says, maybe this is better place for some discussion and thoughts.
I still have some n00b questions so forgive me please. I have read https://security.googleblog.com/2017/05/oss-fuzz-five-months-later-and.html and some documentation out there, but still hold my horses with sharing some weapons like fuzz targets without think.
Should I run fuzz target for some grace period to see if it not founds some easy bugs, and if so - report them first privately, to fulfill responsible disclosure?
After that, post the fuzz target to upstream of fuzzed project, inform rest about improvement or so?
Thanks for answers!
Metadata
Metadata
Assignees
Labels
No labels