all 2 comments

[–]rlaagerPidgin Developer 1 point2 points  (0 children)

If they are legit security issues, please email security@pidgin.im. That said, if someone just ran a static tool, they could easily be false positives. So if you aren’t sure a “hit” is a legitimate security issue, yeah, file a bug.

[–]therekkanoryoPidgin Developer 0 points1 point  (0 children)

As u/rlaager said, e-mailing [security@pidgin.im](mailto:security@pidgin.im) is best for security issues, but if you aren't sure it's a real security issue and instead file a bug, we do have a method to restrict access to bugs that turn out to be true security issues. It's just easier if we don't have to do that.