Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to report a security‒vulnerable plugin registered in the Marketplace? #578

Open
kkm000 opened this issue Aug 27, 2024 · 1 comment

Comments

@kkm000
Copy link

kkm000 commented Aug 27, 2024

The title says it. I obviously can't disclose the plugin name and the nature of the vulnerability publicly, but the plugin should be pulled off the Marketplace until the issue is resolved, and active users warned. What is the security contact for the Marketplace?

Other "marketplaces" (VS Code/VS plugins, browser extensions, Google Workplace extensions, you name it) have a Report button, and reports are always promptly acted upon with due diligence. Hint, hint. :-)

X-Ref: ‘Add the security “Report Plugin” button in Marketplace’, logseq discussion board

@xyhp915
Copy link
Collaborator

xyhp915 commented Aug 28, 2024

Thank you for your suggestion. We will add this entrance soon in app.

Also, just added the relevant instructions in the README.
https://github.com/logseq/marketplace?tab=readme-ov-file#how-to-report-an-unavailable-or-malicious-plugin

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants