spesmilo / spesmilo/electrum

Comprehensive documentation/labelling of past security vulnerabilities?

Open
#4,495 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
8.6k
Forks
3.5k
Avg merge
2d 8h
Merged PRs (30d)
61

Description

Is there a comprehensive list of past security weaknesses and the version they were fixed in anywhere?

For example, I notice that there is a security label in the issue tracker here, which should in theory provide such a list.

When I search for it, however, I also notice that issue #3374— a critical security flaw by any reckoning— is not properly tagged.

As a new user, this immediately raises alarm bells for me: If information on known vulnerabilities is not properly indexed and publicly available, then how can I be sure that I've done everything I can to protect my funds? It makes it difficult to make informed decisions and IMO it hurts credibility as well since such critical information shouldn't be left unorganized.

Proper tagging of issues on this issue tracker would fix this, as could a dedicated page in the documentation.

IDK if this is maybe not an issue because there haven't been any other critical security flaws; but then again, I can't know because there doesn't seem to be much documentation or organization in that regard.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing issues carrying the security label, especially issue #3374, and check how each vulnerability was resolved and in which version. Compare organizing the issue tracker with creating a dedicated documentation page. Done means users can find a comprehensive public list of past security weaknesses, their fixed versions, and consistent indexing.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.