Skip to content

Conversation

@nikic
Copy link
Member

@nikic nikic commented Jul 9, 2023

When submitting a new issue, there is already a "Report a security vulnerability" option for creating a GH security advisory. Remove the additional link for creating a security issue on bugs.php.net.

When submitting a new issue, there is alread a "Report a security
vulnerability" option for creating a GH security advisory. Remove
the additional link for creating a security issue on bugs.php.net.
@nikic nikic requested review from TimWolla and iluuu1994 as code owners July 9, 2023 07:25
Copy link
Contributor

@GrahamCampbell GrahamCampbell left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we explicitly tell people where to report them, still?

@iluuu1994
Copy link
Member

@GrahamCampbell There's already a link to GitHub security advisories.

There are still ongoing internal discussions on whether we want to exclusively switch to GitHub a.k.a. Microsoft for this type of sensitive data. I believe though that GitHub will (or probably already is) the de facto platform people use because nobody wants to use bugs.php.net, demonstrated by the fact that essentially all security issues have been create here since enabling the option.

@iluuu1994
Copy link
Member

#11538 was faster, so I merged that one.

@iluuu1994 iluuu1994 closed this Aug 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants