Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
This is an update to our `SECURITY.md` (since the old one looks to have been lifted from GitHub a few years ago).

This resolves #59
  • Loading branch information
jpmcb committed May 3, 2024
1 parent 95f3212 commit e1ac63d
Showing 1 changed file with 16 additions and 4 deletions.
20 changes: 16 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,19 @@
# GitHub Security Policy
# OpenSauced Security Policy

GitHub's [Bug Bounty program](https://bounty.github.com) rewards researchers for discovering security vulnerabilities in a number of repositories. The full list of projects that are eligible for rewards are [available on our Bug Bounty site](https://bounty.github.com/#scope).
If you believe you have discovered a potential security issue or vulnerability in OpenSauced, one of the OpenSauced experimental products, our backend systems, services we use, or anything that may compromise the integrity and well-being of our platform, please disclose it to us by emailing [[email protected]](mailto:[email protected]). Please do not report security vulnerabilities through public GitHub issues, pull requests, discussions, or any other public forum. Only report issues via the [[email protected]](mailto:[email protected]) email. An engineer from our team will be in touch with you as soon as possible.

If the repository is eligible for rewards, you can submit a report via [HackerOne](https://hackerone.com/github). You can find more useful information in our [rules](https://bounty.github.com/#rules) and [FAQ](https://bounty.github.com/#faqs).
### What to Include in Your Report?

For repositories not covered by the Bug Bounty program, please open an issue.
Your report should include:

- A clear description of the issue, including steps to reproduce it.
- Any details you think would help us understand the potential impact of the vulnerability.
- Information about your system, the software you are using (such as Chrome, Firefox, Safari, etc.), and how you discovered the vulnerability.

### What to Expect After Reporting a Vulnerability?

Once submitted, your report will be reviewed by our engineering team. We will then work with you to understand more about the issue and, if verified, make all efforts to address the vulnerability promptly.

We appreciate your efforts in keeping our community, users, and products safe. Thank you for your support in responsibly disclosing any issues.

Bug bounty rewards are issued on a case-by-case basis and are at the discretion of OpenSauced leadership.

0 comments on commit e1ac63d

Please sign in to comment.