Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider referencing disclosure-check to find a maintainer's preferred contact mechanism #53

Open
scovetta opened this issue Mar 27, 2024 · 0 comments

Comments

@scovetta
Copy link

We have a (still) PoC tool called disclosure-check, intended to help finders locate the best way to privately contact a maintainer.

Image

It looks through SECURITY.md, Security Insights, package metadata, inclusion in Tidelift, and everything else I could think of -- attempting to automate what a human would do when trying to find the right person/process to follow. It supports all of the major ecosystems (npm, pypi, debian, github, maven, etc.) and is available as a Python package.

If someone within the BEST WG would be interested in helping to maintain the project, we can definitely get it over the finish line.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant