The HackerOne nodejs program appears to only cover security bugs in Node.js core. When creating a new H1 report the only option for "Asset" is https://github.com/nodejs/node.
Besides core, there are a range of other assets controlled by the Node.js organization: websites, build pipelines and associated infrastructure, for example.
What's the right channel for responsible disclosure of issues in those non-core areas?
The HackerOne nodejs program appears to only cover security bugs in Node.js core. When creating a new H1 report the only option for "Asset" is https://github.com/nodejs/node.
Besides core, there are a range of other assets controlled by the Node.js organization: websites, build pipelines and associated infrastructure, for example.
What's the right channel for responsible disclosure of issues in those non-core areas?