Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Commit aedf2a4

Browse filesBrowse files
authored
doc: mention DEPENDENCY custom field for H1 reports
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: #64634 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
1 parent 3437feb commit aedf2a4
Copy full SHA for aedf2a4

1 file changed

+2Lines changed: 2 additions & 0 deletions

File tree

Expand file treeCollapse file tree
Open diff view settings
Filter options
Expand file treeCollapse file tree
Open diff view settings
Collapse file

‎doc/contributing/security-release-process.md‎

Copy file name to clipboardExpand all lines: doc/contributing/security-release-process.md
+2Lines changed: 2 additions & 0 deletions
  • Display the source diff
  • Display the rich diff
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,8 @@ The current security stewards are documented in the main Node.js
6767
* [ ] 3\. **Assigning Severity and Writing Team Summary:**
6868
* [ ] Assign a severity and write a team summary on HackerOne for the reports
6969
chosen in the `vulnerabilities.json`.
70+
* [ ] If a report targets a Node.js dependency, such as `undici` or `llhttp`,
71+
make sure to update the `DEPENDENCY` custom field on HackerOne.
7072
* Run `git node security --sync` to update severity and summary in
7173
`vulnerabilities.json`.
7274

0 commit comments

Comments
0 (0)
Morty Proxy This is a proxified and sanitized view of the page, visit original site.