Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Inquiry regarding vulnerability disclosure #68

Closed
quasar098 opened this issue Jan 8, 2024 · 3 comments
Closed

Inquiry regarding vulnerability disclosure #68

quasar098 opened this issue Jan 8, 2024 · 3 comments
Assignees
Labels

Comments

@quasar098
Copy link
Contributor

I originally wanted to disclose a vulnerability, but am lost.

The ./pyproject.toml states modelscan is at version 0.0.0, and the latest release is 0.3.0.

Both of these are not applicable to the security policy, it seems (they are not conforming to 1.X)

image

Are vulnerabilities to be reported currently, or maybe not?

@chrisking
Copy link
Member

Great catch @quasar098 . @seanpmorgan can you take a look at this and update the .toml file?

@quasar098 if you haven't already done so outside of this issue, please checkout https://github.com/protectai/modelscan/blob/main/SECURITY.md and we'll start the triage process on your findings.

@seanpmorgan
Copy link
Member

Hi @quasar098 thanks for filing this ticket! Couple of things:

  1. I merged a PR that updates our security policy to include 0.x versions. As chris mentioned, please go ahead and submit vulnerabilities as directed in SECURITY.md

  2. The library version in pyproject.toml gets overwritten when we publish as a tagged version. This is an easy deployment process for us, but I'm in agreement that it can make it difficult to know the current version by viewing main branch. We're working on a solution to update this in an automated way.

  3. We just cut release v0.4.0 today so that is the current version that has been published to pypi.

  4. Part of that release included two (one, two) security patches from picklescan. Is this what you had in mind for your disclosure or is it something else?

Thanks again!

@quasar098
Copy link
Contributor Author

quasar098 commented Jan 9, 2024

there is that, and more. sending an email regarding it soon

i've done it

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants