From b6eb89348ba49bf5e1e20b7dae6a4290bcbb4702 Mon Sep 17 00:00:00 2001 From: mjac0bs Date: Fri, 6 Sep 2024 07:44:55 -0700 Subject: [PATCH 1/4] Update security.txt in manager package --- .../manager/public/.well-known/security.txt | 20 +++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/packages/manager/public/.well-known/security.txt b/packages/manager/public/.well-known/security.txt index 2e874fff756..228df60423e 100644 --- a/packages/manager/public/.well-known/security.txt +++ b/packages/manager/public/.well-known/security.txt @@ -1,4 +1,16 @@ -Contact: disclosure@linode.com -Encryption: https://keybase.io/linodesecurity/pgp_keys.asc -Policy: https://hackerone.com/linode -Hiring: https://linode.com/careers \ No newline at end of file +# Akamai uses HackerOne for responsible disclosure using +# separate, invite-only programs for specific scopes: +# Akamai CDN: https://hackerone.com/akamai?type=team +# Akamai Connected Cloud / Linode: https://hackerone.com/linode?type=team +Policy: https://www.akamai.com/site/en/documents/akamai/2024/security-research-agreement.pdf + +# In addition, we welcome _all_ types of security reports via email: +Contact: mailto:security@akamai.com +Encryption: https://www.akamai.com/us/en/multimedia/documents/infosec/akamai-security-general.pub + +# Please send abuse reports to: +Contact: mailto:abuse@akamai.com + +Hiring: https://www.akamai.com/careers + +Preferred-Languages: en \ No newline at end of file From 7f409edd6857258f28b96f75aa6e75e4e6f354a1 Mon Sep 17 00:00:00 2001 From: mjac0bs Date: Fri, 6 Sep 2024 07:46:48 -0700 Subject: [PATCH 2/4] Convert root .txt to .MD file --- SECURITY.md | 23 +++++++++++++++++++++++ security.txt | 4 ---- 2 files changed, 23 insertions(+), 4 deletions(-) create mode 100644 SECURITY.md delete mode 100644 security.txt diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000000..ded328c23c7 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Akamai uses HackerOne for responsible disclosure using separate, invite-only programs for specific scopes + +## Akamai CDN + + + +## Akamai Connected Cloud / Linode + +https://hackerone.com/linode?type=team +Policy: https://www.akamai.com/site/en/documents/akamai/2024/security-research-agreement.pdf + +## In addition, we welcome _all_ types of security reports via email + +Contact: mailto:security@akamai.com +Encryption: https://www.akamai.com/us/en/multimedia/documents/infosec/akamai-security-general.pub + +## Please send abuse reports to + +Contact: mailto:abuse@akamai.com + +Hiring: https://www.akamai.com/careers + +Preferred-Languages: en diff --git a/security.txt b/security.txt deleted file mode 100644 index 2e874fff756..00000000000 --- a/security.txt +++ /dev/null @@ -1,4 +0,0 @@ -Contact: disclosure@linode.com -Encryption: https://keybase.io/linodesecurity/pgp_keys.asc -Policy: https://hackerone.com/linode -Hiring: https://linode.com/careers \ No newline at end of file From 8592fba122d6cc2a98be8a3c0a7d9dc54560d175 Mon Sep 17 00:00:00 2001 From: mjac0bs Date: Fri, 6 Sep 2024 07:51:22 -0700 Subject: [PATCH 3/4] Added changeset: Update security policy --- .../manager/.changeset/pr-10902-changed-1725634282672.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 packages/manager/.changeset/pr-10902-changed-1725634282672.md diff --git a/packages/manager/.changeset/pr-10902-changed-1725634282672.md b/packages/manager/.changeset/pr-10902-changed-1725634282672.md new file mode 100644 index 00000000000..736d4a6fa3a --- /dev/null +++ b/packages/manager/.changeset/pr-10902-changed-1725634282672.md @@ -0,0 +1,5 @@ +--- +"@linode/manager": Changed +--- + +Update security policy ([#10902](https://github.com/linode/manager/pull/10902)) From 951d4d0c4df7ac65399976177146e2f35f8040ad Mon Sep 17 00:00:00 2001 From: mjac0bs Date: Fri, 6 Sep 2024 08:21:14 -0700 Subject: [PATCH 4/4] Fix line breaks and linter complaints --- SECURITY.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index ded328c23c7..0a8bb822749 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -6,18 +6,20 @@ ## Akamai Connected Cloud / Linode -https://hackerone.com/linode?type=team -Policy: https://www.akamai.com/site/en/documents/akamai/2024/security-research-agreement.pdf + + +Policy: ## In addition, we welcome _all_ types of security reports via email Contact: mailto:security@akamai.com -Encryption: https://www.akamai.com/us/en/multimedia/documents/infosec/akamai-security-general.pub + +Encryption: ## Please send abuse reports to Contact: mailto:abuse@akamai.com -Hiring: https://www.akamai.com/careers +Hiring: Preferred-Languages: en