Trying to get in touch regarding a security issue #5376

Closed
opened 2025-12-29 19:27:17 +01:00 by adam · 1 comment
Owner

Originally created by @JamieSlome on GitHub (Sep 16, 2021).

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

Originally created by @JamieSlome on GitHub (Sep 16, 2021). Hey there! I'd like to report a security issue but cannot find contact instructions on your repository. If not a hassle, might you kindly add a `SECURITY.md` file with an email, or another contact method? GitHub [recommends](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future. Thank you for your consideration, and I look forward to hearing from you! (cc @huntr-helper)
adam closed this issue 2025-12-29 19:27:17 +01:00
Author
Owner

@jeremystretch commented on GitHub (Sep 16, 2021):

Hi, I'm the lead maintainer for NetBox. I'm afraid we don't have the resources to support a separate triage workflow for security issues. For now, you're welcome to email me directly at jstretch@ns1.com if you're not comfortable opening a bug report for this.

Edit: For anyone alarmed by this post, it seems that the poster has been spamming this same exact message to hundreds of repos recently, many of which are not even Python projects.
Screenshot_2021-09-16 JamieSlome - Overview

@jeremystretch commented on GitHub (Sep 16, 2021): Hi, I'm the lead maintainer for NetBox. I'm afraid we don't have the resources to support a separate triage workflow for security issues. For now, you're welcome to email me directly at jstretch@ns1.com if you're not comfortable opening a bug report for this. Edit: For anyone alarmed by this post, it seems that the poster has been spamming this same exact message to hundreds of repos recently, many of which are not even Python projects. ![Screenshot_2021-09-16 JamieSlome - Overview](https://user-images.githubusercontent.com/13487278/133622388-64467188-136b-4093-9d76-333735a156dd.png)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#5376