nextcloud / nextcloud/server

Appropriate location for vulnerability scanning questions?

Open
#64,265 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

Hi,

Let me start by saying I did read over https://nextcloud.com/security/ and I am aware of https://hackerone.com/nextcloud . However this seems to be for supporting the actual reporting of known vulnerabilities.

I am not a researcher. I work for a large open source company in a highly technical role, but I am not in security. I pointed some vuln scanners at my own nextcloud as part of hygiene to make sure things are working as expected. I ended up with some questions which are not the same as filing a report. I also don't want to cause noise on a serious channel if it turns out my questions are very n00bish.

Where is an appropriate place to ask questions about what I am looking at in the output of my scans?

Let me be clear. I AM NOT ASKING FOR A TUTORIAL. I have specific questions about things I have already done. For example in RHEL and Ubuntu they backport security patches so the version of the software (say apache) is often a false-flag. These are the types of things I would like to ask about Nextcloud and the libraries therein

Thank you

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked Nextcloud security page and HackerOne guidance, then identify whether either resource names a channel for questions about vulnerability-scanner results. Done means documenting or confirming the appropriate place to ask these questions without treating them as vulnerability reports.

Written by the indexing model from the issue text.

Assessment

Tech stack
apache, php, ubuntu
Domain
documentation, security
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.