Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new Vulnerability Response Document #597

Merged
merged 1 commit into from
Jan 4, 2018

Conversation

TheCharlatan
Copy link
Contributor

This document introduces a guide and some rules on how to report vulnerabilities found in the Gridcoin Research Client. It also contains a step by step procedure for the respondents to follow. It has been lifted from the monero repository and was instated there after a major vulnerability was found and patched.

Currently I listed myself as the only respondent. As soon as I get the emails and pgp fingerprints of @denravonska and @gridcoin , or another member of the community that has been identified to be suitable for this role, I will remove myself from the list and add them instead.

Please do suggest changes to the time-frames, correspondence and disclosure media and overall workflow.

Only merge this pr, once the appropriate emails and pgp keys have been collected.

@TheCharlatan
Copy link
Contributor Author

I added ravon's pgp key and email. @gridcoin , I can lead you through the process of generating the key, if you want to.

@tomasbrod
Copy link
Member

You can add mine, If you want,
A3AB 2616 664E BA36 A4EC 3F88 B6B9 BD36 C45F 4253

@TheCharlatan
Copy link
Contributor Author

I added Brod's key and email as well. Since @gridcoin is probably no longer interested in this, I'd ask both @denravonska and @tomasbrod to check their fingerprints again and then merge.

Copy link
Member

@tomasbrod tomasbrod left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My key is OK.

@denravonska
Copy link
Member

Same.

@denravonska denravonska merged commit 4db3dcd into gridcoin-community:master Jan 4, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants