-
Notifications
You must be signed in to change notification settings - Fork 4.6k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Create SECURITY.md #2000
Create SECURITY.md #2000
Conversation
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
Hey @0xfatty How are you? Could you help me understand a bit more what is the best approach to support this doc? |
Hi @ogabrielluiz , Thank you for reaching out. First of all, I do apologize for not putting much detailed information into my commit. Creating a The purpose of How to best approach this: I hope my wording makes sense. Please feel free to let me know if there are any other questions or concerns. I will be more than happy to assist. Given Langflow is getting a lot of attention from public with over 18k stars, this would even strengthen its reputation and help keep its users safe. References:[1] https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/publishing-a-repository-security-advisory |
In my understanding, this request seems to define a method for collecting security issues like data injection and proposes a template for directly reporting security concerns in GitHub's security tab. In Langflow, remote code changes through APIs or UI are possible, and since the Langflow core team is handling the barriers, it seems that they are seeking more extensive participation from contributors. https://github.com/kanboard/kanboard/security I would like to share that in one of the projects I have been paying attention to, this approach is being managed effectively. |
Given that Langflow's API and code logic inherently require meticulous management, and the migration to tools like Zustand or Casbin is still underway, it doesn't seem like the right time to consider this document. |
Initializing Security report policies page