web form to report security issues

Open
#17 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
hugo
Domain
security, web-dev

Research direction

Start by reading the Apache Security website sources and the reporting guidance at https://www.apache.org/security/#reporting-a-vulnerability, then review the OpenSSF Best Practices vulnerability_report_private requirement. No implementation file or test is named; done means agreeing on and documenting a private web-form flow that produces complete security reports and satisfies that requirement.

Written by the indexing model from the issue text.

Description

It might be nice to provide a web form to submit security issues.

Such a form could nudge people towards providing quality/complete reports, and would be a way for projects to pass the "the project MUST include how to send the information in a way that is kept private" vulnerability_report_private requirement of the OpenSSF Best Practices badge (now that we removed our public keys from https://www.apache.org/security/#reporting-a-vulnerability)

Dominant language
CSS
Stars
14
Forks
16
Avg merge
1d 6h
Merged PRs (30d)
16

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/security-site

All issues in apache/security-site

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.