Skip to content

SECURITY_CONTACTS contact information #56

@tallclair

Description

@tallclair

SECURITY_CONTACTS files currently use github user names, but github doesn't have private messaging, and users don't always have public email addresses.

We need a better solution, so that the PSC is able to reach out to the security contacts through a private channel. A few ideas include:

  1. deprecate SECURITY_CONTACTS, and adopt github's new security advisory functionality
  2. maintain a private contact information database for security contacts (bleh)
  3. Just require email addresses in addition to github user IDs

/help

Metadata

Metadata

Assignees

Labels

help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions