jupyter / jupyter/security

Communicating security-related issues/topics to Jupyter developers

Open
#9 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
27
Forks
12
Avg merge
3d 5h
Merged PRs (30d)
3

Description

At today's Jupyter community call @sgibson91 mentioned the recent [Travis CI issue](https://arstechnica.com/information-technology/2021/09/travis-ci-flaw-exposed-secrets-for-thousands-of-open-source-projects/) and whether we had a process for alerting Jupyter developers about those kinds of vulnerabilities. What are the best processes/procedures for getting the word out? We've got, or could use:

- Discourse (but are security posts visible enough there, and not everyone looks at it)
- Email lists (probably not a lot of excitememt about a new one)
- The Jupyter blog has been used to make statements about security
- Some way to identify Jupyter projects on GitHub and automatically open issues on them (?)

Other ideas?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.