Skip to content

How to report a security‒vulnerable plugin registered in the Marketplace? #578

@kkm000

Description

@kkm000

The title says it. I obviously can't disclose the plugin name and the nature of the vulnerability publicly, but the plugin should be pulled off the Marketplace until the issue is resolved, and active users warned. What is the security contact for the Marketplace?

Other "marketplaces" (VS Code/VS plugins, browser extensions, Google Workplace extensions, you name it) have a Report button, and reports are always promptly acted upon with due diligence. Hint, hint. :-)

X-Ref: ‘Add the security “Report Plugin” button in Marketplace’, logseq discussion board

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions