A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://www.mediawiki.org/wiki/Special:MyLanguage/Reporting_security_bugs below:

Reporting security bugs - MediaWiki

This is the process for reporting security issues in software and services maintained or operated by Wikimedia Foundation. This includes MediaWiki and Wikimedia projects such as Wikipedia.

We support responsible disclosure and we hope that anyone who finds a potential security issue in our ecosystem acts with discretion and forbearance.

What is considered a security issue

This is a general outline and not an exhaustive listing of the scope of this process.

Reporting a security issue

To report an issue, email security@wikimedia.org or use the Report Security Issue form on Phabricator.

Such reports will not be publicly visible at the time of reporting. See below for further process once issues are resolved.

What to include in a security issue report

If you report the vulnerability by email to security@wikimedia.org, let us know if you have a Wikimedia Phabricator account as we will add you to the bug we create, so you can track the status.

Phabricator accounts can be created using an existing SUL Wiki account.

What happens when security issues are reported

We will:

Crediting reporters

When possible during the remediation process, the security bugs should have comments that include:

Reporter access to their own authored reports is standard, but to gain access to security protected issues generally there is a separate process

Contributing patches

If you would like to provide a patch for a security bug, please add it as an attachment to the Phabricator task. You can either drag-and-drop the patch into the comment area, or include a diff of the patch as a comment.

Please do not submit patches to Gerrit. All Gerrit changes (including "drafts") are publicly accessible.


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4