Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent users to report security issues via GitHub issues #285

Closed
ppalaga opened this issue Oct 2, 2024 · 4 comments
Closed

Prevent users to report security issues via GitHub issues #285

ppalaga opened this issue Oct 2, 2024 · 4 comments

Comments

@ppalaga
Copy link
Contributor

ppalaga commented Oct 2, 2024

We just got a security issue reported for QCXF (not linking it here intentionally).

Quarkus has this warning in the new issue form:

image

I wonder whether we could adopt similar measures for Quarkiverse projects too?

There is also this Privately reporting a security vulnerability feature of GitHUb that we perhaps might consider enabling?

@gastaldi
Copy link
Member

gastaldi commented Oct 3, 2024

There is also this Privately reporting a security vulnerability feature of GitHUb that we perhaps might consider enabling?

That requires integrations/terraform-provider-github#2399 to be implemented. For now we can enable them individually in a manual basis.

@ppalaga
Copy link
Contributor Author

ppalaga commented Oct 3, 2024

For now we can enable them individually in a manual basis.

Could you please enable it for Quarkus CXF?

@gastaldi
Copy link
Member

gastaldi commented Oct 3, 2024

For now we can enable them individually in a manual basis.

Could you please enable it for Quarkus CXF?

Of course, done.

@gastaldi
Copy link
Member

gastaldi commented Oct 3, 2024

I've enabled that by default in the Organization settings (https://github.com/organizations/quarkiverse/settings/security_products). It's now enabled in all Quarkiverse repositories.

@gastaldi gastaldi closed this as completed Oct 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants