ChanServ changed the topic of #sandstorm to: Welcome to #sandstorm: home of all things Sandstorm and Cap'n Proto. Say hi! | Have a question but no one is here? Try asking in the discussion group: https://groups.google.com/group/sandstorm-dev | Channel logs available at https://libera.irclog.whitequark.org/sandstorm
rektide has joined #sandstorm
TMM_ has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
TMM_ has joined #sandstorm
xet7 has joined #sandstorm
xet7 has quit [Remote host closed the connection]
TMM_ has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
TMM_ has joined #sandstorm
xet7 has joined #sandstorm
xet7 has quit [Ping timeout: 245 seconds]
xet7 has joined #sandstorm
Durandal has joined #sandstorm
Durandal has quit [Client Quit]
Durandal has joined #sandstorm
Durandal has quit [Client Quit]
Durandal has joined #sandstorm
<Durandal> Hello,
<Durandal> where can i report a security issue with sandstorm please?
<ocdtrekkie> Hi!
<kentonv> security@sandstorm.io
<Durandal> Ok thx!
Durandal has quit [Client Quit]
Durandal has joined #sandstorm
<ocdtrekkie> @kentonv I figured that address existed but it is not easy to confirm right now.
<Durandal> Good evening to you all!
<kentonv> ocdtrekkie, yeah it should probably be in the docs somewhere if it isn't currently....
<Durandal> couldn't find any adress directly so i showed up here in irc ;-)
<Durandal> might be somethibg i found but not 100% sure
<ocdtrekkie> SECURITY.md in the repo and/or security.txt on the web domain might be a good choice.
<kentonv> I'm looking forward to reading your report, Durandal
<ocdtrekkie> (Durandal, did you try checking for either of those... they don't exist but I'm curious which would've been most readily found by you)
<Durandal> Ok i try looking again tomorrow and let you know. Was not looking to intensive this evening as we had sone friends over for a visit
<Durandal> Havent tried with google fu to search for it
<Durandal> Do you use pgp for reporting or can i send directly?
<kentonv> You can just send directly. I don't think anyone is going to be MITMing security reports to a small open source project. :)
<Durandal> Thats true ;-) its my second time i found something odd the first time was with SAP they take reports only via PGP
Durandal has quit [Quit: Connection closed]
jfred has quit [Remote host closed the connection]
jfred has joined #sandstorm
xet7 has quit [Quit: Leaving]
cwebber has quit [Ping timeout: 240 seconds]
strugee has quit [Ping timeout: 248 seconds]
strugee_ has joined #sandstorm
abliss has quit [Ping timeout: 240 seconds]
iFire[m] has quit [Ping timeout: 252 seconds]
timmc[m] has quit [Ping timeout: 256 seconds]
jryans has quit [Ping timeout: 268 seconds]
isd has quit [Ping timeout: 276 seconds]
ocdtrekkie has quit [Ping timeout: 272 seconds]