Skip to content

Conversation

@Luna5-threshold
Copy link
Contributor

@Luna5-threshold Luna5-threshold commented May 4, 2023

This is a first draft to update the security policies across repositories with the immunefi bug bounty information after its launch (and first amendment) Requesting review and feedback on language @mhluongo @mswilkison @cygnusv @pdyraga @derekpierre

@cygnusv cygnusv requested a review from pdyraga May 4, 2023 13:43
cygnusv
cygnusv previously approved these changes May 4, 2023
SECURITY.md Outdated

## Reporting a Vulnerability Not Covered by the Bug Bounty Program

For those assets that are not covered in the Immunefi Bug Bounty program, (please see the updated program [here](https://immunefi.com/bounty/thresholdnetwork/)), if you identify any vulnerabilities within the Threshold Network code and outside our bounty program, please let us know. You can send an email to `security@threshold.network` with relevant information about your findings. We will work with researchers to coordinate vulnerability disclosure between our stakers, partners, and users to ensure the successful mitigation of vulnerabilities.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we prefer people to report out-of-scope issues to security@threshold.network or to just use immunefi anyway since we can escalate/scope in anything that's sufficiently important

Copy link
Contributor Author

@Luna5-threshold Luna5-threshold May 5, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would like to get more inputs on this issue, that’s a very good question

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, let's funnel everything through immunefi

cygnusv
cygnusv previously approved these changes Jun 7, 2023
Copy link
Member

@derekpierre derekpierre left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎸

Luna5-threshold and others added 7 commits June 7, 2023 17:10
This is a first draft to update the security policies across repositories with the immunefi bug bounty information after its launch (and first amendment) 
Requesting review and feedback on language
Co-authored-by: MacLane S Wilkison <maclane@nucypher.com>
Co-authored-by: Derek Pierre <derek.pierre@gmail.com>
This is a review of language on the security policy taking into account the given feedback to funnel all bugs through the Immunefi program. Please check if everything is correct.
removing assets out-of-scope to avoid duplicated maintenance of the list, and also making modifications regarding the severity classification of impacts (v2.2 -> v2.3)
remove spaces
Co-authored-by: Derek Pierre <derek.pierre@gmail.com>
@cygnusv cygnusv merged commit 3ed292e into threshold-network:main Jun 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants