nebula icon indicating copy to clipboard operation
nebula copied to clipboard

Create `SECURITY.md`

Open jasikpark opened this issue 2 years ago • 2 comments

It would be great to have a SECURITY.md like a README.md so it's possible to responsibly disclose bugs in the nebula source code.

I would make a PR, but I'm unsure what more on would entail past recommending emailing [email protected] or [email protected] or something + mentioning the bug bounty program at https://hackerone.com/slack?type=team

image

Github sets up a nice template if you go to https://github.com/slackhq/nebula/security/policy to create a new policy

image

jasikpark avatar Jun 28 '22 20:06 jasikpark

We have #481 and #263 we can review as well

wadey avatar Jun 28 '22 20:06 wadey

It seems like #481 is the more descriptive of the two, though it's not up-to-date with the new salesforce bug severity scale..

Is it worth merging one of those and then updating it? Or should it be added in a whole other PR?

jasikpark avatar Jun 30 '22 10:06 jasikpark