pull down to refresh
100 sats \ 10 replies \ @ek 30 Apr \ parent \ on: What would you do, if you were in the team behind SN? meta
Thank you.
All information regarding how to do a responsible disclosure should be in our README here, in the FAQ or here. I thought these are pretty common locations.
@holonite, where did you look? Where should we put it such that people can find it?
I was initially planning to DM you with these but now I'll upload it via GitHub.
I think there should be another page link in the SN header as a pinned post for 7 days in suppose glowing neon saying "Beginners here!" for accounts that are not atleast 1 week old. I will include other ideas in the GitHub issue.
reply
reply
And the link I shared to the security advisory page on the GH repo
reply
lol, after all that
reply
reply
- Same https://github.com/stackernews/stacker.news/issues/2144#issuecomment-2845280638
- i was wrong - i thought the credits settings form was exploitable
reply