Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Responsible disclosure policy #110

Open
cornelius opened this issue Mar 13, 2019 · 0 comments
Open

Responsible disclosure policy #110

cornelius opened this issue Mar 13, 2019 · 0 comments
Labels
documentation Documentation process About the way we work
Milestone

Comments

@cornelius
Copy link
Member

We need a policy defining how security issues in our code can be reported to us, i.e. we need a responsible disclosure policy.

One example illustrating why this is needed and what are the important points is described in Cory Field's post about disclosing a vulnerability in Bitcoin Cash.

Having a security@ email address is part of that (see #39).

@cornelius cornelius added process About the way we work documentation Documentation labels Mar 13, 2019
@thothd thothd added this to the 0.1 milestone Mar 13, 2019
@thothd thothd modified the milestones: 0.1, 1.0 Apr 3, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Documentation process About the way we work
Projects
None yet
Development

No branches or pull requests

2 participants