|
Message-Id: <EEF3C292-40F0-4EF5-A4D8-3731FA2FE428@chromium.org> Date: Sun, 24 Jul 2022 11:10:35 -0700 From: Roxana Bradescu <roxxbee@...il.com> To: oss-security@...ts.openwall.com Subject: Re: snowflakedb security contacts > On Jul 18, 2022, at 5:18 PM, Seth Arnold <seth.arnold@...onical.com> wrote: > > Hello, if anyone has friends or acquaintances at snowflakedb, please > direct their attention to: > > https://github.com/snowflakedb/gosnowflake/issues/619 > "Please add a SECURITY.md file and security policy" > > I don't know if what I found is actually an issue but I'd like to give > them a chance to see it privately before telling the whole world. I've > not had much luck with the Usual Methods so far. > > Everyone else: *please* take five minutes to write down how you'd like > people to report security issues. Some people subscribe to the "security > bugs are just bugs, report them like any other" philosophy. Some people > want a chance to look at potential security issues privately, first. > > Whatever you'd like, please just write it down someplace obvious. > > Thanks Hi Seth, did you ever get a response from anyone at Snowflake? Just in case you didn’t, Snowflake uses HackerOne for their vuln mgmt program so issues get reported to HackerOne directly (and this information belongs in a Security.md file) https://hackerone.com/139c0e4f-5b34-470a-b81e-aa8740c3e66e/embedded_submissions/new <https://hackerone.com/139c0e4f-5b34-470a-b81e-aa8740c3e66e/embedded_submissions/new> --- Regards, Roxana Content of type "text/html" skipped Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.