Conversation
|
Review requested:
|
|
Maybe this bug bounty section can be removed? |
|
... or to be consistent with the blog post, say "Security Bug Bounty Program Paused" and link to the blog post for details |
|
It's best that AI-Sloop users see this explicitly, to avoid submitting invalid reports in an attempt at brute-force bounties. |
| The Node.js project engages in an official bug bounty program for security | ||
| researchers and responsible public disclosures. The program is managed through | ||
| the HackerOne platform. See <https://hackerone.com/nodejs> for further details. | ||
| The Node.js project no longer has a bug bounty program. |
There was a problem hiding this comment.
I would still mention hackerone though saying we have a program but dont pay bounties
There was a problem hiding this comment.
It's still mentioned in Line 5
Line 5 in 12249cc
There was a problem hiding this comment.
https://hackerone.com/nodejs is still showing an active bug bounty program, so currently it would be confusing to have a link to it in the section which says there is no longer a bug bounty program
https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties