-
Notifications
You must be signed in to change notification settings - Fork 66
Open
Labels
help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.Indicates that an issue or PR should not be auto-closed due to staleness.
Description
SECURITY_CONTACTS files currently use github user names, but github doesn't have private messaging, and users don't always have public email addresses.
We need a better solution, so that the PSC is able to reach out to the security contacts through a private channel. A few ideas include:
- deprecate SECURITY_CONTACTS, and adopt github's new security advisory functionality
- maintain a private contact information database for security contacts (bleh)
- Just require email addresses in addition to github user IDs
/help
justaugustus
Metadata
Metadata
Assignees
Labels
help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.Indicates that an issue or PR should not be auto-closed due to staleness.