Which @angular/* package(s) are the source of the bug?
service-worker
Is this a regression?
Yes
Description
@josephperrott, from Google VRP:
“You would need to convince the Angular team that there is a security impact significant enough, e.g. to warrant a security advisory, for us to consider a reward in OSS VRP.”
As I have stated previously, and as you yourself are aware since both you and I are credited on this critical severity finding, GHSA-x288-3778-4hhx, VRP triage can be extremely dismissive. I went back and forth with VRP for over a month on that critical severity finding. They told me it had no security impact until it was brought here, and then things finally moved along.
This time around, I submitted a security-relevant fix, #67494, which was merged by the Angular team. But I am still seeing the same dismissive approach. I am completely done with Google OSS VRP after this, but I should still be paid for the work I have already done.
The fix I mentioned was accepted by your team and merged into your repo. Google OSS VRP is now adding extra conditions to avoid payout.
I am posting here because I am hoping to get some support from your team. I provided a fix that was merged into the Angular repo. Hopefully that counts for something. And again, I believe that work should be paid for, especially since the fix was security-relevant.
Please provide a link to a minimal reproduction of the bug
No response
Please provide the exception or error you saw
Please provide the environment you discovered this bug in (run ng version)
Anything else?
No response
Which @angular/* package(s) are the source of the bug?
service-worker
Is this a regression?
Yes
Description
@josephperrott, from Google VRP:
“You would need to convince the Angular team that there is a security impact significant enough, e.g. to warrant a security advisory, for us to consider a reward in OSS VRP.”
As I have stated previously, and as you yourself are aware since both you and I are credited on this critical severity finding, GHSA-x288-3778-4hhx, VRP triage can be extremely dismissive. I went back and forth with VRP for over a month on that critical severity finding. They told me it had no security impact until it was brought here, and then things finally moved along.
This time around, I submitted a security-relevant fix, #67494, which was merged by the Angular team. But I am still seeing the same dismissive approach. I am completely done with Google OSS VRP after this, but I should still be paid for the work I have already done.
The fix I mentioned was accepted by your team and merged into your repo. Google OSS VRP is now adding extra conditions to avoid payout.
I am posting here because I am hoping to get some support from your team. I provided a fix that was merged into the Angular repo. Hopefully that counts for something. And again, I believe that work should be paid for, especially since the fix was security-relevant.
Please provide a link to a minimal reproduction of the bug
No response
Please provide the exception or error you saw
Please provide the environment you discovered this bug in (run
ng version)Anything else?
No response