Skip to content

Commit 2b16def

Browse files
committed
Blog: New HackerOne Signal Requirement for reports
1 parent 3dd2deb commit 2b16def

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

apps/site/pages/en/about/security-reporting.mdx

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,12 @@ For more details on active Security Policies, checkout [this page](https://githu
1111

1212
Report security bugs in Node.js via [HackerOne](https://hackerone.com/nodejs).
1313

14+
> **Note:** Submitting a report through HackerOne requires a minimum
15+
> [Signal](https://docs.hackerone.com/en/articles/8369891-signal-impact) score of **1.0**.
16+
> If your Signal score is below this threshold, please reach out to the Node.js
17+
> security release stewards directly via the
18+
> [OpenJS Foundation Slack](https://slack-invite.openjsf.org/) instead.
19+
1420
Normally, your report will be acknowledged within 5 days, and you'll receive
1521
a more detailed response to your report within 10 days indicating the
1622
next steps in handling your submission. These timelines may extend when

0 commit comments

Comments
 (0)