The growing popularity of the project + an increase of AI-powered security enthusiasts submitting random bugs has created a HUGE backlog for the Foregejo security team.
Instead of acting like this, the author should offer to help the project.
coordinated disclosure has always been a courtesy (with a deadline to motivate the vendor to fix their stuff) and i don't like how people seem to just expect it now
Comments
The growing popularity of the project + an increase of AI-powered security enthusiasts submitting random bugs has created a HUGE backlog for the Foregejo security team.
Instead of acting like this, the author should offer to help the project.
I think the author would argue they did try to do so, but their efforts were poorly received.
The author doesn’t owe forgejo anything. They are doing them a favor by highlighting the issues
No, the author is seeking attention. He is not doing forgejo or their users any favours by completely ignoring the rules of engagement
https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc...
coordinated disclosure has always been a courtesy (with a deadline to motivate the vendor to fix their stuff) and i don't like how people seem to just expect it now