Skip to content

Where to report non-core nodejs security bugs? #776

Description

@rcowsill

The HackerOne nodejs program appears to only cover security bugs in Node.js core. When creating a new H1 report the only option for "Asset" is https://github.com/nodejs/node.

Besides core, there are a range of other assets controlled by the Node.js organization: websites, build pipelines and associated infrastructure, for example.

What's the right channel for responsible disclosure of issues in those non-core areas?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions