GitHub now allows enabling private vulnerability reporting at scale

29 tháng 4, 2023

GitHub announced that private vulnerability reporting is now generally available and can be enabled at scale, on all repositories belonging to an organization.

Once toggled on, security researchers can use this dedicated communications channel to privately disclose security issues to an open-source project's maintainers without accidentally leaking vulnerability details.


This is "a private collaboration channel that makes it easier for researchers and maintainers to report and fix vulnerabilities on public repositories," GitHub's Eric Tooley and Kate Catlin said.


Since its introduction as an opt-in feature in November 2022 during the GitHub Universe 2022 global developer event, "maintainers for more than 30k organizations have enabled private vulnerability reporting on more than 180k repositories, receiving more than 1,000 submissions from security researchers."


Easy to enable across an org's repos


During the public beta test phase, the option to report private vulnerabilities could only be activated by maintainers and repository owners only on single repositories.


Starting this week, they can now enable this direct bug-reporting channel for all repositories within their organization.


GitHub has also added integration and automation support via a new repository security advisories API that enables dispatching private reports to third-party vulnerability management systems and submitting the same report to multiple repos sharing a security flaw.


It can also be configured so private bug reporting is enabled automatically on all new public repositories.


The functionality can be enabled under 'Code security and analysis' by clicking the 'Enable all' button next to the 'Private vulnerability reporting' option.



Enabling private vulnerability reporting (GitHub)


​Owners and administrators of public repositories should toggle private vulnerability reporting to ensure they receive bug reports on the same platform where they get resolved, discuss all details with researchers, and securely collaborate with them to create a patch.


After it's enabled, security researchers can submit private security reports directly on GitHub from the Security tab under the repository name by clicking on the 'Report a vulnerability' in the left sidebar, under Reporting > Advisories.


Private bug reports can also be sent via the GitHub REST API using the parameters described on this documentation page.

Last month, GitHub also announced that its secret scanning alerts service is now generally available for all public repositories.


Source: bleepingcomputer.com

Bạn cũng có thể quan tâm

4 tháng 6, 2024
Bộ định tuyến chơi game TP-Link Archer C5400X dễ mắc phải các lỗi bảo mật có thể cho phép kẻ tấn công từ xa, không được xác thực thực thi các lệnh trên thiết bị.
3 tháng 6, 2024
Ngày 27 tháng 5 Check Point đã cảnh báo rằng các tác nhân đe dọa đang nhắm mục tiêu vào các thiết bị VPN truy cập từ xa của Check Point trong một chiến dịch đang diễn ra nhằm xâm phạm mạng doanh nghiệp.
31 tháng 5, 2024
Công ty quản lý đơn thuốc Sav-Rx cảnh báo hơn 2,8 triệu cá nhân ở Hoa Kỳ việc họ đã bị vi phạm dữ liệu và dữ liệu cá nhân của họ đã bị đánh cắp trong một cuộc tấn công mạng năm 2023.
Thêm bài viết
Share by: