Skip to content

Conversation

@dodo920306
Copy link
Contributor

No description provided.

dodo920306 and others added 4 commits June 29, 2025 04:02
Bumps the npm_and_yarn group with 3 updates in the /src/dashboard directory: [body-parser](https://github.com/expressjs/body-parser), [express](https://github.com/expressjs/express) and [pbkdf2](https://github.com/crypto-browserify/pbkdf2).


Updates `body-parser` from 1.20.3 to 2.0.0
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.3...2.0.0)

Updates `express` from 4.21.2 to 5.0.0
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/master/History.md)
- [Commits](expressjs/express@4.21.2...v5.0.0)

Updates `pbkdf2` from 3.1.2 to 3.1.3
- [Changelog](https://github.com/browserify/pbkdf2/blob/master/CHANGELOG.md)
- [Commits](browserify/pbkdf2@v3.1.2...v3.1.3)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 2.0.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: express
  dependency-version: 5.0.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: pbkdf2
  dependency-version: 3.1.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <[email protected]>
@dodo920306 dodo920306 changed the title Fix broken code of conduct link Update docs links Jun 29, 2025
SECURITY.md Outdated
If you think you have discovered a security issue in any of the Hyperledger projects, we'd love to hear from you. We will take all security bugs seriously and if confirmed upon investigation we will patch it within a reasonable amount of time and release a public security bulletin discussing the impact and credit the discoverer.

There are two ways to report a security bug. The easiest is to email a description of the flaw and any related information (e.g. reproduction steps, version) to [security at hyperledger dot org](mailto:[email protected]).
There are two ways to report a security bug. The easiest is to email a description of the flaw and any related information (e.g. reproduction steps, version) to [security at lists dot hyperledger dot org](mailto:security@lists.hyperledger.org).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

From https://www.lfdecentralizedtrust.org/, we should use the hackerone to report security bugs.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OK. Should we also include GitHub Security Advisories as a way to do so?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Guess LFDT has its own security advisory, but we can also mention the github one.

SECURITY.md Outdated
The other way is to file a confidential security bug in our [JIRA bug tracking system](https://jira.hyperledger.org). Be sure to set the “Security Level” to “Security issue”.

The process by which the Hyperledger Security Team handles security bugs is documented further in our [Defect Response page](https://wiki.hyperledger.org/display/HYP/Defect+Response) on our [wiki](https://wiki.hyperledger.org).
The other way is to file a confidential security bug in our [GitHub Issues](https://github.com/hyperledger-cello/cello/issues).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

github issues are public, so it's not a good way to report security bug. Let's remove this way.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reasonable.

dodo920306 and others added 3 commits July 1, 2025 10:52
Since GitHub issues are public, it's not a good way to report security
vulnerabilities there, so they should be removed from SECURITY.md
as a proper way to do so.

Signed-off-by: Yu-Lin "Kirin" Chu <[email protected]>
* [Mail List](mailto:hyperledger-cello@lists.hyperledger.org): General technical topics with Cello project.
* [Wikipage](https://lf-hyperledger.atlassian.net/wiki/spaces/cello/overview): Lots of information and documentation about the project, e.g., meeting schedule, design doc.
* [Mail List](mailto:cello@lists.lfdecentralizedtrust.org): General technical topics with Cello project.
* [Discord](https://discord.gg/hyperledger): Real-time online discussions.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We are not using discord now. So better remove this line.

@yeasy yeasy merged commit a5e7e58 into hyperledger-cello:main Jul 7, 2025
3 checks passed
@dodo920306 dodo920306 deleted the fix/broken-code-of-conduct-ref branch July 8, 2025 01:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants