-
Notifications
You must be signed in to change notification settings - Fork 176
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
README.md, section Currently Supported Threats, needs a legend #233
Comments
Hi - the legend is not written in stone - we were looking for unique identifiers with at least a semblance of separation between them. The categorization was never too strict simply because the issue never came up, and the identifiers are mostly used for allow-listing known issues. It is great you want to add threats! If you're not comfortable with adding them to the existing label scheme, feel free to create your own. It would be great if it followed the ??[0-9][0-9]* format, though. |
The grouping of the threats is a little bit over the place and sometimes it just unclear to me as well what the letters are supposed to mean. But a threat is a threat and it does not matter if it is a denial of service or an information disclosure as long as it is a valid threat to the system. That being said here is my understanding of the first letters of all the threats. AA deals with AuthN ( no idea what the second A is for, maybe this was once AuthN and AuthZ) |
Hey folks, Is the mailing list used anymore? The mailing list is advertised as https://groups.google.com/g/pytm-users. If not, can you email me so we can have an offline conversation? My email address is noloader, gmail account. |
Actually I don't now if the mailing list was ever used. I am on that list for over a year and cannot remember a conversation there. |
@noloader perhaps the slack is the best place for an off-github discussion. |
There is a slack? |
Ping me on the owasp slack and l will send you an invitation.
…On Mon, Apr 1, 2024, 17:54 Raphael Ahrens ***@***.***> wrote:
There is a slack?
—
Reply to this email directly, view it on GitHub
<#233 (comment)>, or
unsubscribe
<https://github.com/notifications/unsubscribe-auth/AAC2BAJ6MVZJJBCKWGMZNDTY3HJP3AVCNFSM6AAAAABENENEYCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDAMZQGYZDSNZQGU>
.
You are receiving this because you commented.Message ID:
***@***.***>
|
Hi Everyone,
We are trying to add some threats to the Pytm sources. We are trying to figure out which categories to use for the threats. The categories are causing use trouble.
Here are some examples:
The table for Currently Supported Threats needs a legend. Or README.md needs a section discussing the Categories.
It would be very helpful if the project documented the legend for the naming scheme.
The text was updated successfully, but these errors were encountered: