Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security page has outdated info #1014

Open
drouhard opened this issue May 1, 2023 · 3 comments
Open

Security page has outdated info #1014

drouhard opened this issue May 1, 2023 · 3 comments

Comments

@drouhard
Copy link

drouhard commented May 1, 2023

https://emberjs.com/security/

This page asking for help in #emberjs, which hasn't been around for years. It also says the best way to get security updates is to sign up for the Ember Security mailing list, but I can see that hasn't had a post since 2015.

At a minimum these details should be removed. As an Ember consumer it makes me question how much of this page is factual, and how I can ensure I am on top of security vulnerabilities 😬

@MinThaMie
Copy link
Contributor

I've contacted @kategengler and I'll create a PR. Thanks for brining this to our attention!

@kategengler
Copy link
Contributor

I want to assure anybody reading this page that the security email address is monitored and the people currently listed are involved enough that they would let others on the team know if they were contacted directly.

The most incorrect piece of info is #emberjs, which should be #dev-ember-js and is referring to a Discord channel (the discord server is mentioned again in the next sentence).

We have dropped the ball on notifying the security mailing list. We had no security issues to send to the list after those from 2016 until November 2022. We applied for a CVE number but were never issued one.

Another place to monitor is the tag on the blog https://blog.emberjs.com/tag/security

@drouhard
Copy link
Author

drouhard commented May 9, 2023

Thank you for the update!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants