Skip to content

Fix #13: Bug Bounty Request#14

Open
Stackwyre wants to merge 1 commit into
polybase:mainfrom
Stackwyre:fix/464-bug-bounty-request
Open

Fix #13: Bug Bounty Request#14
Stackwyre wants to merge 1 commit into
polybase:mainfrom
Stackwyre:fix/464-bug-bounty-request

Conversation

@Stackwyre
Copy link
Copy Markdown

Resolves #13

Changes

  • SECURITY.md

Fixes #13

Tested locally. Happy to address any review feedback.

@loopghost
Copy link
Copy Markdown

Hey @Stackwyre , thanks for taking care of this so quickly. I really appreciate the team’s commitment to improving the security disclosure process.

I reviewed the new SECURITY.md and it looks good to me overall.

One small suggestion: under “Contact the maintainers directly”, it would be helpful to clarify which platform those handles refer to, for example GitHub, X, Telegram, etc. Right now it may not be immediately clear to external researchers how they should reach out through those handles.

Regarding the bug bounty section, HackenProof could be worth considering when the team is ready to move forward with a formal program. Personally, as a Web3 security researcher, I’ve had very good experiences with HackenProof, and I’d be happy to make an introduction to their team privately. They also have a strong network of Web3 security researchers.

Thanks again for the quick response here. Once the maintainer contact channels are clarified, I’d be happy to follow up privately as well.

Copy link
Copy Markdown

@loopghost loopghost left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Under “Contact the maintainers directly”, it would be helpful to clarify which platform those handles refer to, for example GitHub, X, Telegram, etc. Make sure to be publicly reachable through that contact method (i.e. having your DMs open to everyone if it's X). Right now it may not be immediately clear to external researchers how they should reach out through those handles.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug Bounty Request

2 participants