-
-
Notifications
You must be signed in to change notification settings - Fork 7
docs: add YesWeHack policy #90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Co-authored-by: Wes Todd <[email protected]>
Co-authored-by: Jon Church <[email protected]>
|
|
||
| ### Bug bounty description | ||
|
|
||
| | Scope Type | Scope | Asset value | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Note for myself: Check that the npm versions are correctly deprecated and aligned with the LTS plan. Only express was verified
bjohansebas
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
| - Oversee the advisory & CVE request process if applicable. | ||
| - Escalate critical vulnerabilities when necessary. | ||
| - Track all security reports for visibility and reporting. | ||
| - Handle communications and disputes on the YesWeHack platform (if needed) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
do we want to keep the (if needed) ? I guess we will always communicate there is an issue was reported on YWH?
they changed their name and redir to the new domain
jonchurch
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
pending the deprecation version check that @UlisesGascon left a todo about:
#90 (comment)
The program is not yet public (login and team addition is required) https://yeswehack.com/business-units/sovereign-tech-fund/programs/express-js-bug-bounty-program
This will require the review from the @expressjs/security-triage and @expressjs/express-tc. Also we will need to wait for the feedback from STF and YesWeHack team (before merging) 👍
Related