When a security researcher finds a security bug, what do they do? Unfortunately, the answer sometimes is they search for the appropriate people to notify and, when they can’t be found, end up posting the vulnerability to public email lists, the GitHub project, or even Twitter. . This is the problem that security platform HackerOne and software supply chain management tool Sonatype have teamed up to solve with The Central Security Project, a new effort that “brings together the ethical hacker and open source communities to streamline the process for reporting and resolving vulnerabilities discovered in libraries housed in The Central Repository, the world’s largest collection of open source components,” according to a statement. The link for this article located at TheNewStack is no longer available. . GitHub partners with Snyk to enhance security audits for public Python packages, aiming to boost safety and reliability in the open source ecosystem. Vulnerability Reporting, Open Source Projects, Java Security, HackerOne Collaboration, Ethical Hacking. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.