Re: [PEAR-DEV] Where to report a security issue in pear?

[email protected] ("Jesus M. Castagnetto") Wed, 11 Aug 2021 12:41:52 -0500
Newsgroups php.pear.dev
Message-ID <CAP3+WLBhnNmb20aPdQ=wVXCazg5nBuCjOH6ibTT2+XqqPWFKzg@mail.gmail.com>
--000000000000e5569005c94c2207
Content-Type: text/plain; charset="UTF-8"

Hi Pavel,

Speaking as a PEAR dinosaur that hasn't done anything for years, but still
remembers how we handled things (I am old but not *that* old :-)

Usually sec issues were shared with the PEAR group (
https://pear.php.net/group/), the details hashed with them, patches were
reviewed, and projects that were known to depend on the package or packages
affected were contacted to alert them of the problem.

Once all that was done and we knew the issue was patched (in particular in
other FLOSS projects that used the libs), it was announced along with the
new version of the package (or packages).

My guess is that something like this would be the way to go.

Cheers.


--
Jesus M. Castagnetto, Ph.D. <[email protected]>
Web site: https://castagnetto.site
Github: https://github.com/jmcastagnetto
LinkedIn: https://www.linkedin.com/in/jesuscastagnetto/
ORCID: https://orcid.org/0000-0002-7188-1605


On Wed, Aug 11, 2021 at 5:05 AM Pavel Heimlich <[email protected]>
wrote:

> Hi,
> is there a place to report a security issue in pear itself without
> divulging it to the general public?
>
> Thank you
>
> P.
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>

--000000000000e5569005c94c2207--