Skip to content

Latest commit

 

History

History
22 lines (14 loc) · 1.2 KB

SECURITY.md

File metadata and controls

22 lines (14 loc) · 1.2 KB

Security Policy

This document describes the management of vulnerabilities for the doxie-node project and it's officials' plugins.

Reporting vulnerabilities

Individuals who find potential vulnerabilities in doxie-node are invited to complete a vulnerability issue via the dedicated HackerOne tool for Node.js modules: https://hackerone.com/nodejs-ecosystem.

How to report a vulnerabiliy

It is of the utmost importance that you read carefully HOW TO REPORT A VULNERABILIY written by the Security Working Group of Node.js.

Handling vulnerability reports

When a potential vulnerability is reported and confirmed the doxie-node Core Team.

Members of this team are expected to keep all information that they have privileged access to by being on the team completely private to the team. This includes agreeing to not notify anyone outside the team of issues that have not yet been disclosed publicly, including the existence of issues, expectations of upcoming releases, and patching of any issues other than in the process of their work as a member of the doxie-node Core team.