I'm not sure we should have this #security channel (stream) on Zulip. I'm concerned it encourages people to discuss security vulnerabilities in public.
At https://guides.dataverse.org/en/6.0/installation/config.html#reporting-security-issues we say "If you have a security issue to report, please email it to security@dataverse.org."
What do others think?
There's a little more background on what happens AFTER someone emails security@dataverse.org at https://guides.dataverse.org/en/6.0/developers/security.html if that's of interest.
Last updated: Nov 01 2025 at 14:11 UTC