Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trying to get in touch regarding a security issue #229

Closed
JamieSlome opened this issue Sep 11, 2021 · 6 comments · Fixed by #293
Closed

Trying to get in touch regarding a security issue #229

JamieSlome opened this issue Sep 11, 2021 · 6 comments · Fixed by #293

Comments

@JamieSlome
Copy link

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

@Envek
Copy link
Member

Envek commented Sep 11, 2021

@JamieSlome, hey, thank you for reaching out!

Please send details of security related issue to email surrender@evilmartians.com with topic containing "Lefthook” and we will take care of it.

Later we will figure out proper contact details, I will keep this issue open for now.

@Envek
Copy link
Member

Envek commented Sep 14, 2021

We have received the email with details, looking into issue right now. Thank you!

@masukomi
Copy link

masukomi commented Jul 6, 2022

this ticket still being open implies there's an unaddressed security issue for ~10 months. I assume that's not actually the case.

@JamieSlome
Copy link
Author

@Envek
Copy link
Member

Envek commented Jul 7, 2022

This ticket is open only because we haven't declared a way to send security-related reports to us. Thanks for the heads up!

I investigated this initial security issue and it seems to be unsolvable because Lefthook by design executes arbitrary commands from its config file. If you don't trust some repository, don't use lefthook in it.

If you have any additional thoughts, feel free to comment!

Envek added a commit that referenced this issue Jul 7, 2022
@JamieSlome
Copy link
Author

@Envek - just an idea, but you could always point to:

https://huntr.dev/repos/evilmartians/lefthook

@Envek Envek closed this as completed in #293 Jul 7, 2022
Envek added a commit that referenced this issue Jul 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants