-
-
Notifications
You must be signed in to change notification settings - Fork 6.5k
Blog: Add hackerone new policy #8559
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Co-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
👋 Codeowner Review RequestThe following codeowners have been identified for the changed files: Team reviewers: @nodejs/releasers Please review the changes when you have a chance. Thank you! 🙏 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR adds a blog post announcing a new policy requiring HackerOne Signal score of 1.0 or higher for submitting vulnerability reports to the Node.js project. The policy aims to reduce the burden of low-quality reports on the security team.
Changes:
- New blog post announcing HackerOne Signal requirement for vulnerability submissions
- Explains rationale (increase in low-quality reports) and alternative contact methods for researchers below the threshold
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8559 +/- ##
=======================================
Coverage 75.01% 75.01%
=======================================
Files 103 103
Lines 9036 9037 +1
Branches 311 311
=======================================
+ Hits 6778 6779 +1
Misses 2256 2256
Partials 2 2 ☔ View full report in Codecov by Sentry. |
|
Lighthouse Results
|
📦 Build Size ComparisonSummary
Changes➕ Added Assets (1)
➖ Removed Assets (1)
|
|
Let's just make sure @mcollina checks it before landing |
mcollina
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm
cc: @nodejs/tsc @nodejs/security-release