![]() |
FOSSology Advancing open source analysis and development |
|
Table of Contents
Known Security Risks (0.6.1)The first release of FOSSology has not been through a thorough security audit and is not recommended for general-purpose wide-spread use. The known security risks are as follows:
Mitigation OptionsTo mitigate the risks, we have taken the following precautions and recommend the following steps:
RewriteEngine On
RewriteCond %{REQUEST_URI} .*('|"|`|%22|%27|%60|").* [OR]
RewriteCond %{REQUEST_URI} .*(/\.\./).*
RewriteRule ^.*$ - [F]
Security ContactShould you come across any known or potential security risks, please contact security@fossology.org. Be sure to provide enough information so that we can reproduce and validate the risk. We take security very seriously. However, there are not many of us so it may take a few days for us to respond (especially on weekends and holidays). Thank you for your understanding and reporting efforts. FOSSology Project documentation is licensed under the GNU Free Documentation License Version 1.2 | |||