Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bounty for ecosystem package: pilot program #525

Closed
vdeturckheim opened this issue May 1, 2019 · 6 comments
Closed

Bounty for ecosystem package: pilot program #525

vdeturckheim opened this issue May 1, 2019 · 6 comments

Comments

@vdeturckheim
Copy link
Member

vdeturckheim commented May 1, 2019

HackerOne suggests we define a list of pilot projects we would mark as eligible for bounties if vulnerabilites are reported into. I have an arbitrary list (based on popularity and how maintained I feel these projects are):

wdyt?

@lirantal
Copy link
Member

lirantal commented May 1, 2019

@vdeturckheim this is very much connected to #503 so we can't really start without that being resolved either.

@dougwilson
Copy link
Member

Based on what has transpired with the finalhandler incident, please do not include Express in this bounty program, as I don't have confidence in the processes that are in place here.

@lirantal
Copy link
Member

lirantal commented May 7, 2019

We could probably add some of Matteo's projects to that list as he is pretty active on them as well and they're popular too (/cc @mcollina)

@vdeturckheim
Copy link
Member Author

Good point for @mcollina 's repos!

@mhdawson
Copy link
Member

mhdawson commented May 9, 2019

I'm ok with the list provided we get opt-in by the maintainers.

@lirantal
Copy link
Member

handled in #593 so closing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants