Skip to content
Snippets Groups Projects
SECURITY.md 960 B
Newer Older
syuilo's avatar
syuilo committed
# Reporting Security Issues

Amelia Yukii's avatar
Amelia Yukii committed
If you discover a security issue in Sharkey, please report it by sending an
email to [admin@transfem.org](mailto:admin@transfem.org).
syuilo's avatar
syuilo committed

This will allow us to assess the risk, and make a fix available before we add a
Amelia Yukii's avatar
Amelia Yukii committed
bug report to the GitLab repository.
syuilo's avatar
syuilo committed

Thanks for helping make Sharkey safe for everyone.
syuilo's avatar
syuilo committed

かっこかり's avatar
かっこかり committed
> [!note]
> CNA [requires](https://www.cve.org/ResourcesSupport/AllResources/CNARules#section_5-2_Description) that CVEs include a description in English for inclusion in the CVE Catalog.
> 
> When creating a security advisory, all content must be written in English (it is acceptable to include a non-English description along with the English one).

syuilo's avatar
syuilo committed
## When create a patch

If you can also create a patch to fix the vulnerability, please create a PR on the private fork.

> [!note]
> There is a GitHub bug that prevents merging if a PR not following the develop branch of upstream, so please keep follow the develop branch.