Security concern #304

Closed
opened 2026-02-04 19:32:31 +03:00 by OVERLORD · 3 comments
Owner

Originally created by @JamieSlome on GitHub (Sep 17, 2022).

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@vautia) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

Originally created by @JamieSlome on GitHub (Sep 17, 2022). Hello 👋 I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@vautia) has found a potential issue, which I would be eager to share with you. Could you add a `SECURITY.md` file with an e-mail address for me to send further details to? GitHub [recommends](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future. Looking forward to hearing from you 👍 (cc @huntr-helper)
Author
Owner

@zackpollard commented on GitHub (Sep 17, 2022):

Hey Jamie,

We will absolutely get that setup, if you want to discuss this faster if you join the discord I can add you to a secure channel where we can discuss this. Discord is in the README.

Cheers!

@zackpollard commented on GitHub (Sep 17, 2022): Hey Jamie, We will absolutely get that setup, if you want to discuss this faster if you join the discord I can add you to a secure channel where we can discuss this. Discord is in the README. Cheers!
Author
Owner

@alextran1502 commented on GitHub (Sep 17, 2022):

Hi @JamieSlome , if you don't use Discord, you can also email me at alex.tran1502@gmail.com and I can relay the message back to the team!

Thank you for helping us looking into this

@alextran1502 commented on GitHub (Sep 17, 2022): Hi @JamieSlome , if you don't use Discord, you can also email me at alex.tran1502@gmail.com and I can relay the message back to the team! Thank you for helping us looking into this
Author
Owner

@zackpollard commented on GitHub (Oct 1, 2022):

SECURITY.md was added

@zackpollard commented on GitHub (Oct 1, 2022): SECURITY.md was added
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: immich-app/immich#304