Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create SECURITY.md #2545

Closed
wants to merge 1 commit into from
Closed

Create SECURITY.md #2545

wants to merge 1 commit into from

Conversation

KOSASIH
Copy link

@KOSASIH KOSASIH commented Feb 4, 2024

No description provided.

@Botspot
Copy link
Owner

Botspot commented Feb 4, 2024

Hello @KOSASIH, I am not sure how familiar you are with pi-apps as a project structure.
In all likelihood, if there is ever a security incident involving pi-apps, the problem will be due to a vulnerability found in one of the apps. In nearly all cases, Pi-Apps will download the necessary app files straight from the original project developers. If an issue arises, the problem should be reported to the devs of that app, and once it is fixed then all our users will receive the fix in the form of an ordinary app update.

Have you thought through these types of scenarios, and would you be willing to take some thought to tailor a potential SECURITY.md to better fit the pi-apps project structure? For one minor example of why a standard SECURITY.md file would be a poor fit here: pi-apps does have any version numbers, meaning the entire section on which versions are 'supported', does not apply here.

@theofficialgman
Copy link
Collaborator

@Botspot same user as last time #2429

It is likely an annoying bot they have running that automatically generates this crap.

@Botspot
Copy link
Owner

Botspot commented Feb 4, 2024

Bot must be getting good to react to my reply with a 👍.
I'm sure that @KOSASIH will reply here if not a bot. ;)

@KOSASIH
Copy link
Author

KOSASIH commented Feb 5, 2024 via email

@Botspot
Copy link
Owner

Botspot commented Feb 5, 2024

I'm not Bot.. ☺ i'm contributor of your project... KOSASIH

Well then, @KOSASIH, please respond to the commentI made earlier, which you can refer back to using this link.

@theofficialgman
Copy link
Collaborator

theofficialgman commented Feb 5, 2024

@Botspot don't bother. The user @KOSASIH has been spam opening PRs like this for many months now. I see that they have opened many for repositories for the github user https://github.com/pi-apps , which is why they have mistakenly called themselves "a contributor of our project". We have no affiliation with the Pi Network.

@KOSASIH
Copy link
Author

KOSASIH commented Feb 6, 2024

@Botspot I see open flaws in your system, so I suggest completing a security system. I have cloned your repo and added many files to complete it as a form of my contribution to your project. This is based on the idea that it can help improve your project.

Thank you.

@Botspot
Copy link
Owner

Botspot commented Feb 6, 2024

@Botspot I see open flaws in your system, so I suggest completing a security system. I have cloned your repo and added many files to complete it as a form of my contribution to your project. This is based on the idea that it can help improve your project.

Thank you.

All your commits as seen here are low-quality and demonstrate zero understanding with how our project works.
@KOSASIH, you have been banned from all Botspot repositories and you are not welcome to contact us any more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants