[Security Issue] Is someone maintaining gogs? #7900
Replies: 3 comments
-
Beta Was this translation helpful? Give feedback.
-
Hi, thanks for your passion and careness here! While we wouldn't be able to review your security report and confirm the triage during our last batch of work, the report sequence is honored when we request CVEs from GitHub when we get to it. Meanwhile, if you have means to request CVEs out-of-band, you're welcome to do so as some of the GHSAs we have published did, and in that case, we will simply attach the CVE number directly to GHSA (if deemed to publish one in the first place). You should also feel free to send pull requests at any time, and we will review at our earliest convenience. Please be patient as no one is paid to work on this project, and everyone has their life. |
Beta Was this translation helpful? Give feedback.
-
Hi @unknwon, thanks for the reply.
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I've opened a security issue 4 months ago and no one replied.
The latest version (0.13.2) is still vulnerable.
Does someone care about this product?
Beta Was this translation helpful? Give feedback.
All reactions