-
Notifications
You must be signed in to change notification settings - Fork 122
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bounty for ecosystem package: pilot program #525
Comments
@vdeturckheim this is very much connected to #503 so we can't really start without that being resolved either. |
Based on what has transpired with the finalhandler incident, please do not include Express in this bounty program, as I don't have confidence in the processes that are in place here. |
We could probably add some of Matteo's projects to that list as he is pretty active on them as well and they're popular too (/cc @mcollina) |
Good point for @mcollina 's repos! |
I'm ok with the list provided we get opt-in by the maintainers. |
handled in #593 so closing |
HackerOne suggests we define a list of pilot projects we would mark as eligible for bounties if vulnerabilites are reported into. I have an arbitrary list (based on popularity and how maintained I feel these projects are):
Express (all packages under the GH org)(Bounty for ecosystem package: pilot program #525 (comment))wdyt?
The text was updated successfully, but these errors were encountered: