Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 24 Jul 2022 11:10:35 -0700
From: Roxana Bradescu <roxxbee@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: snowflakedb security contacts


> On Jul 18, 2022, at 5:18 PM, Seth Arnold <seth.arnold@...onical.com> wrote:
> 
> Hello, if anyone has friends or acquaintances at snowflakedb, please
> direct their attention to:
> 
> https://github.com/snowflakedb/gosnowflake/issues/619
> "Please add a SECURITY.md file and security policy"
> 
> I don't know if what I found is actually an issue but I'd like to give
> them a chance to see it privately before telling the whole world. I've
> not had much luck with the Usual Methods so far.
> 
> Everyone else: *please* take five minutes to write down how you'd like
> people to report security issues. Some people subscribe to the "security
> bugs are just bugs, report them like any other" philosophy. Some people
> want a chance to look at potential security issues privately, first.
> 
> Whatever you'd like, please just write it down someplace obvious.
> 
> Thanks

Hi Seth, did you ever get a response from anyone at Snowflake?

Just in case you didn’t, Snowflake uses HackerOne for their vuln mgmt program so issues get reported to HackerOne directly (and this information belongs in a Security.md file)
https://hackerone.com/139c0e4f-5b34-470a-b81e-aa8740c3e66e/embedded_submissions/new <https://hackerone.com/139c0e4f-5b34-470a-b81e-aa8740c3e66e/embedded_submissions/new>

---
Regards, Roxana



Content of type "text/html" skipped

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.