Allure Report - security checks and protection measures #2669
-
Hope you're doing well! What measures do you have in place to prevent any malicious packages from being downloaded via Allure? To help us feel confident about using Allure, can you share some details on:
Getting some insights on these points would really help us trust that Allure is safe to use. Thanks a lot for your help! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Allure Report is an open-source project supported by a vast global community. We recognize the importance of establishing robust security policies and diligently addressing all potential security risks and issues. Initially, all repositories in our organization had designated maintainers. These maintainers are senior-level developers with experience in open-source project management. Our full-time employees maintain the core components. Each contribution is visible, open to public discussion, and requires a review from another maintainer. We follow to best coding practices, including:
Allure can function securely in private networks without requiring an internet connection. As all code is open source, you are free to perform any penetration testing or security audit. We are more than happy to assist in addressing any discovered vulnerabilities. |
Beta Was this translation helpful? Give feedback.
Allure Report is an open-source project supported by a vast global community. We recognize the importance of establishing robust security policies and diligently addressing all potential security risks and issues.
Initially, all repositories in our organization had designated maintainers. These maintainers are senior-level developers with experience in open-source project management. Our full-time employees maintain the core components. Each contribution is visible, open to public discussion, and requires a review from another maintainer.
We follow to best coding practices, including: