-
Notifications
You must be signed in to change notification settings - Fork 20
Update security policies with bug bounty info #139
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
SECURITY.md
Outdated
|
|
||
| ## Reporting a Vulnerability Not Covered by the Bug Bounty Program | ||
|
|
||
| For those assets that are not covered in the Immunefi Bug Bounty program, (please see the updated program [here](https://immunefi.com/bounty/thresholdnetwork/)), if you identify any vulnerabilities within the Threshold Network code and outside our bounty program, please let us know. You can send an email to `security@threshold.network` with relevant information about your findings. We will work with researchers to coordinate vulnerability disclosure between our stakers, partners, and users to ensure the successful mitigation of vulnerabilities. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
do we prefer people to report out-of-scope issues to security@threshold.network or to just use immunefi anyway since we can escalate/scope in anything that's sufficiently important
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would like to get more inputs on this issue, that’s a very good question
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good point, let's funnel everything through immunefi
derekpierre
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎸
This is a first draft to update the security policies across repositories with the immunefi bug bounty information after its launch (and first amendment) Requesting review and feedback on language
Co-authored-by: MacLane S Wilkison <maclane@nucypher.com>
Co-authored-by: Derek Pierre <derek.pierre@gmail.com>
This is a review of language on the security policy taking into account the given feedback to funnel all bugs through the Immunefi program. Please check if everything is correct.
removing assets out-of-scope to avoid duplicated maintenance of the list, and also making modifications regarding the severity classification of impacts (v2.2 -> v2.3)
remove spaces
Co-authored-by: Derek Pierre <derek.pierre@gmail.com>
This is a first draft to update the security policies across repositories with the immunefi bug bounty information after its launch (and first amendment) Requesting review and feedback on language @mhluongo @mswilkison @cygnusv @pdyraga @derekpierre