Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Commit 236d7ee

Browse filesBrowse files
RafaelGSSaduh95
authored andcommitted
doc: add CVE delay mention
PR-URL: #61465 Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Juan José Arboleda <soyjuanarbol@gmail.com> Reviewed-By: Beth Griggs <bethanyngriggs@gmail.com> Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
1 parent 8abd54f commit 236d7ee
Copy full SHA for 236d7ee

1 file changed

+15Lines changed: 15 additions & 0 deletions

File tree

Expand file treeCollapse file tree
Open diff view settings
Filter options
Expand file treeCollapse file tree
Open diff view settings
Collapse file

‎SECURITY.md‎

Copy file name to clipboardExpand all lines: SECURITY.md
+15Lines changed: 15 additions & 0 deletions
  • Display the source diff
  • Display the rich diff
Original file line numberDiff line numberDiff line change
@@ -348,6 +348,21 @@ Security notifications will be distributed via the following methods.
348348
* <https://groups.google.com/group/nodejs-sec>
349349
* <https://nodejs.org/en/blog/vulnerability>
350350

351+
### CVE publication timeline
352+
353+
When security releases are published, there is a built-in delay before the
354+
corresponding CVEs are publicly disclosed. This delay occurs because:
355+
356+
1. After the security release, we request the vulnerability reporter to disclose
357+
the details on HackerOne.
358+
2. If the reporter does not disclose within one day, we proceed with forced
359+
disclosure to publish the CVEs.
360+
3. The disclosure then goes through HackerOne's approval process before the CVEs
361+
become publicly available.
362+
363+
As a result, CVEs may not be immediately available when security releases are
364+
published, but will typically be disclosed within a few days of the release.
365+
351366
## Comments on this policy
352367

353368
If you have suggestions on how this process could be improved, please visit

0 commit comments

Comments
0 (0)
Morty Proxy This is a proxified and sanitized view of the page, visit original site.