# Grotere transparantie over de ernst van beveiligingsproblemen

**URL:** https://meta.discourse.org/t/greater-transparency-over-severity-of-security-issues/185241
**Category:** Support
**Created:** [2 april 2021 om 12:34 UTC](https://meta.discourse.org/t/greater-transparency-over-severity-of-security-issues/185241 "2021-04-02T12:34:03Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![core](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/core/32/183957_2.png) [@core](https://meta.discourse.org/u/core)
#### Post date: [2 april 2021 om 12:34 UTC](https://meta.discourse.org/t/greater-transparency-over-severity-of-security-issues/185241/1 "2021-04-02T12:34:03Z")

</div>

I believe the discourse team could do a better job at transparency over security issues. The last one [only says](https://meta.discourse.org/t/2-7-0-beta5-improved-invites-auto-tag-and-auto-replace-watched-words-pm-bulk-operations-and-more/182096/2):

> This beta includes 1 security fix for issues reported by our community and HackerOne 8.
> 
> - Prefer Loofah for processing cooked HTML

And I was not able to find said report on HackerOne.

Ideally the release would include a link to the HackerOne report and the severity of the security issue at hand.

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [2 april 2021 om 14:55 UTC](https://meta.discourse.org/t/greater-transparency-over-severity-of-security-issues/185241/2 "2021-04-02T14:55:07Z")

</div>

Hey @core,

The security fix info is intentionally non-detailed. Sites upgrade at different speeds, while we want to share that there was a security fix, we don’t want to provide detail to allow malicious actors to easily exploit it. The security fix is the commit message, so you can always look at [our GitHub repo](https://github.com/discourse/discourse/search?o=desc&q=SECURITY&s=committer-date&type=Commits) for security commits to see the code changes if you like.

> [@core](#):
>
> Ideally the release would include a link to the HackerOne report

We do not make our HackerOne reports public. While we previously allowed hackers to request disclosure of their reports, due to abuse received after doing so on multiple occasions we discontinued that.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [2 mei 2021 om 14:55 UTC](https://meta.discourse.org/t/greater-transparency-over-severity-of-security-issues/185241/3 "2021-05-02T14:55:16Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
