-
-
Notifications
You must be signed in to change notification settings - Fork 6
Description
Currently, we provide this Security.md as the reference for researchers.
There are somethings that we might want to change, for example the way of reporting:
Report security bugs by emailing the lead maintainer in the Readme.md file.
I will suggest to use a plain email reference or even better an alias so the security triage team can get notify and not individuals. I think that we should provide a way to send secure messages (PGP?).
The lead maintainer will acknowledge your email within 48 hours, and will send a more detailed response within 48 hours indicating the next steps in handling your report.
Maybe we can change this a bit to mimic the Node.js policy:
Normally your report will be acknowledged within 5 days, and you'll receive a more detailed response to your report within 10 days indicating the next steps in handling your submission. These timelines may extend when our triage volunteers are away on holiday, particularly at the end of the year.
By checking the Node.js Security policy I noticed two interesting things:
- They relay in an external bug bounty platform: https://hackerone.com/nodejs/hacktivity and not emails
- They provide security updates using the blog and google groups: https://github.com/nodejs/node/blob/main/SECURITY.md#receiving-security-updates