Skip to content

Appropriate location for vulnerability scanning questions? #64265

Description

@stratus-ss

Hi,

Let me start by saying I did read over https://nextcloud.com/security/ and I am aware of https://hackerone.com/nextcloud . However this seems to be for supporting the actual reporting of known vulnerabilities.

I am not a researcher. I work for a large open source company in a highly technical role, but I am not in security. I pointed some vuln scanners at my own nextcloud as part of hygiene to make sure things are working as expected. I ended up with some questions which are not the same as filing a report. I also don't want to cause noise on a serious channel if it turns out my questions are very n00bish.

Where is an appropriate place to ask questions about what I am looking at in the output of my scans?

Let me be clear. I AM NOT ASKING FOR A TUTORIAL. I have specific questions about things I have already done. For example in RHEL and Ubuntu they backport security patches so the version of the software (say apache) is often a false-flag. These are the types of things I would like to ask about Nextcloud and the libraries therein

Thank you

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions