Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
SECURITY.md to publish vuln reporting process
[skip ci]
- Loading branch information
1 parent
d64b74d
commit 0c97c74
Showing
2 changed files
with
34 additions
and
8 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
# Security and Vulnerability Reporting | ||
|
||
The Loofah core contributors take security very seriously and investigate all reported vulnerabilities. | ||
|
||
If you would like to report a vulnerablity or have a security concern regarding Loofah, please [report it via HackerOne](https://hackerone.com/loofah/reports/new). | ||
|
||
Your report will be acknowledged within 24 hours, and you'll receive a more detailed response within 72 hours indicating next steps in handling your report. | ||
|
||
If you have not received a reply to your submission within 48 hours, there are a few steps you can take: | ||
|
||
* Contact the current security coordinator (Mike Dalessio <mike.dalessio@gmail.com>) | ||
* Email the Loofah user group at loofah@librelist.com (archive at http://librelist.com) | ||
|
||
Please note, the user group list is a public area. When escalating in that venue, please do not discuss your issue. Simply say that you're trying to get a hold of someone from the core team. | ||
|
||
The information you share with the Loofah core contributors as part of this process will be kept confidential within the team, unless or until we need to share information upstream with our dependent libraries' core teams, at which point we will notify you. | ||
|
||
If a vulnerability is first reported by you, we will credit you with the discovery in the public disclosure. |