-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Vulnerabiltiy disclosure program.yaml #110
base: master
Are you sure you want to change the base?
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -9,6 +9,13 @@ criterias: | |
- indicator: >+ | ||
The company has a mechanism (ex: a bug bounty program) through which security researchers can | ||
submit vulnerabilities they discover. | ||
|
||
A company with a bug bounty program has an alternative mechanism to report vulnerabilities that non-technical | ||
consumers can use to report vulnerabilities. | ||
|
||
The company provides a clear description with examples of what is defined as a security vulnerability. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We probably don't want companies to define security vulnerability. So, security researchers can report any finding or concern they have to companies. @billfitzg @mrerecich @stephtngu-CR |
||
|
||
The company provides a security@company email address or submission form that manages vulnerabilities only. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Should we give companies some room for naming their delicate email addresses which is for managing vulnerabilities only? How about "The company provides a delicate email address or submission form that manages vulnerabilities only." |
||
|
||
The company discloses the timeframe in which it will review reports of | ||
vulnerabilities. | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Instead of asking conpanies for having a vulnerability report portal for non-technical consumers, is it ok to say that A company with a bug bounty program has an alternative mechanism to report bugs that non-technical consumers can use.