Skip to content

Conversation

@UlisesGascon
Copy link
Member

@UlisesGascon UlisesGascon commented Jul 17, 2025

The program is not yet public (login and team addition is required) https://yeswehack.com/business-units/sovereign-tech-fund/programs/express-js-bug-bounty-program

This will require the review from the @expressjs/security-triage and @expressjs/express-tc. Also we will need to wait for the feedback from STF and YesWeHack team (before merging) 👍

Related

@UlisesGascon UlisesGascon requested review from a team July 17, 2025 13:42
@UlisesGascon UlisesGascon self-assigned this Jul 17, 2025

### Bug bounty description

| Scope Type | Scope | Asset value |
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note for myself: Check that the npm versions are correctly deprecated and aligned with the LTS plan. Only express was verified

Copy link
Member

@bjohansebas bjohansebas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

- Oversee the advisory & CVE request process if applicable.
- Escalate critical vulnerabilities when necessary.
- Track all security reports for visibility and reporting.
- Handle communications and disputes on the YesWeHack platform (if needed)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we want to keep the (if needed) ? I guess we will always communicate there is an issue was reported on YWH?

they changed their name and redir to the new domain
Copy link
Member

@jonchurch jonchurch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pending the deprecation version check that @UlisesGascon left a todo about:
#90 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Time for a bounty program? Update Security Policies and Procedures

8 participants