Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Commit 2426d3f

Browse filesBrowse files
UlisesGasconmarco-ippolito
authored andcommitted
doc: add security escalation policy
PR-URL: #59806 Refs: openjs-foundation/cross-project-council#1588 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: James M Snell <jasnell@gmail.com>
1 parent 409cb77 commit 2426d3f
Copy full SHA for 2426d3f

File tree

Expand file treeCollapse file tree

1 file changed

+7
-0
lines changed
Open diff view settings
Filter options
Expand file treeCollapse file tree

1 file changed

+7
-0
lines changed
Open diff view settings
Collapse file

‎SECURITY.md‎

Copy file name to clipboardExpand all lines: SECURITY.md
+7Lines changed: 7 additions & 0 deletions
  • Display the source diff
  • Display the rich diff
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,13 @@ you informed of the progress being made towards a fix and full announcement,
1515
and may ask for additional information or guidance surrounding the reported
1616
issue.
1717

18+
If you do not receive an acknowledgement of your report within 6 business
19+
days, or if you cannot find a private security contact for the project, you
20+
may escalate to the OpenJS Foundation CNA at `security@lists.openjsf.org`.
21+
22+
If the project acknowledges your report but does not provide any further
23+
response or engagement within 14 days, escalation is also appropriate.
24+
1825
### Node.js bug bounty program
1926

2027
The Node.js project engages in an official bug bounty program for security

0 commit comments

Comments
0 (0)
Morty Proxy This is a proxified and sanitized view of the page, visit original site.