# Discourse security announcements

**URL:** https://meta.discourse.org/t/discourse-security-announcements/163609
**Category:** Feature
**Created:** [September 10, 2020, 12:24pm UTC](https://meta.discourse.org/t/discourse-security-announcements/163609 "2020-09-10T12:24:56Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![matjay](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@matjay](https://meta.discourse.org/u/matjay)
#### Post date: [September 10, 2020, 12:24pm UTC](https://meta.discourse.org/t/discourse-security-announcements/163609/1 "2020-09-10T12:24:57Z")

</div>

Hi Discourse Developers and Users,

Some of you probably heard about the recent vBulletin zero-day. I realized that something like can happen to every project - even super modern like Discourse.

I realized that I need to start following security feed / mailing list for every project I use. Even if the project has auto-updates I need to get a message about security vulnerabilities so I can manually check that updates were applied. In case of Discourse I’d rebuild Docker to make sure that my forum won’t get hacked in case of known security issue.

I can’t find a specific feed for security news (and nothing else) at Discourse.

Could you please tell me does Discourse have feed / mailing list / blog category / something that shows only security issues and that I can follow / subscribe so I can quickly get an e-mail / notification in case of zero-day or new version that includes security patches?

Thank you

Matt

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [September 10, 2020, 12:29pm UTC](https://meta.discourse.org/t/discourse-security-announcements/163609/2 "2020-09-10T12:29:31Z")

</div>

Here it is

> [@Security RSS feed vs mailing list](https://meta.discourse.org/t/security-rss-feed-vs-mailing-list/97054/3):
>
> I just published the applet that we’ve actually been using: Basically the same, but you can send to any email addresses and post to a slack channel for maximum pingage.

---

<div class="post-metadata">

### Author: ![matjay](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@matjay](https://meta.discourse.org/u/matjay)
#### Post date: [September 10, 2020, 12:44pm UTC](https://meta.discourse.org/t/discourse-security-announcements/163609/3 "2020-09-10T12:44:44Z")

</div>

For some reason I couldn’t find that one. Thank you. RSS feed is the best option:

> **[Build software better, together](https://github.com/search?q=repo%3Adiscourse%2Fdiscourse+SECURITY&type=Commits)**
>
> GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
