Skip to content

Commit bd767c5

Browse files
UlisesGascontargos
authored andcommitted
doc: add security escalation policy
PR-URL: #59806 Refs: openjs-foundation/cross-project-council#1588 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: James M Snell <jasnell@gmail.com>
1 parent acada1f commit bd767c5

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

SECURITY.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,13 @@ you informed of the progress being made towards a fix and full announcement,
1515
and may ask for additional information or guidance surrounding the reported
1616
issue.
1717

18+
If you do not receive an acknowledgement of your report within 6 business
19+
days, or if you cannot find a private security contact for the project, you
20+
may escalate to the OpenJS Foundation CNA at `security@lists.openjsf.org`.
21+
22+
If the project acknowledges your report but does not provide any further
23+
response or engagement within 14 days, escalation is also appropriate.
24+
1825
### Node.js bug bounty program
1926

2027
The Node.js project engages in an official bug bounty program for security

0 commit comments

Comments
 (0)