(no title)
whylo | 3 years ago
You don't have a security.txt, https://infisical.com/docs/security/overview doesn't mention it and it's not on your FAQ, so I don't blame ianpurton for not finding it. You have a 'Report a vulnerability' issue template on GitHub (https://github.com/Infisical/infisical/security/advisories/n...) but then your readme points to a security policy which says to email: https://github.com/Infisical/infisical/security/policy
dangtony98|3 years ago
There's also an issue template for reporting vulnerabilities as well as you mentioned.
That said, we'll add info to the security page in our docs to contact us regarding vulnerabilities.
Thanks!