- Incoming submissions are reports that identify security problems.
- The reporter needs an account on the system.
- Submissions start private; only accessible to the reporter and the curl security team
- All submissions should be disclosed and make public once dealt with. Both correct and incorrect ones.
- There should be a way to discuss the problem amongst security team members, the reporter and per-report invited guests.
- It should be possible to post security-team-only messages that the reporter and invited guests cannot see
- For confirmed vulnerabilities, an advisory will be produced that the system could help fascilitate
- If there's a field for CVE, make it possible to provide our own
- Closed and disclosed reports should be clearly marked as invalid/valid etc
- Reports should have a tagging system so that they can be marked as "AI slop" or other terms for statistical and metric reasons
- Abusive users should be possible to ban/block from this program
- Additional (customizable) requirements for the priveledge of submitting reports is appreciated (rate limit, time since account creation, etc)
Last active
February 9, 2026 22:20
-
-
Save bagder/03684358da1215815c660c545395dfad to your computer and use it in GitHub Desktop.
curl security reporting wishlist
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment