forked from phlex-ruby/phlex
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Signed-off-by: Joel Drapper <joel@drapper.me>
- Loading branch information
1 parent
9e3f5b9
commit 5f9fbb5
Showing
1 changed file
with
2 additions
and
11 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,14 +1,5 @@ | ||
# Security | ||
|
||
If you find a possible security vulnerability, please [send us a private advisory](https://github.com/phlex-ruby/phlex/security/advisories/new). | ||
If you suspect you may have found a security vulnerability, please do not open a public issue or pull request. Instead, please [send us a private advisory](https://github.com/phlex-ruby/phlex/security/advisories/new). | ||
|
||
> [!WARNING] | ||
> Please do not open a public Issue or Pull Request. | ||
## Bug bounty | ||
|
||
There is currently a bounty of $100 USD, kindly sponsored by [Seth Horsley](https://twitter.com/SethHorsley), for the next serious vulnerability responsibly disclosed to us. | ||
|
||
## Bug bounty pot | ||
|
||
If you wish to sponsor a bug bounty for Phlex, please get in touch with Joel at [joel@drapper.me](mailto:joel@drapper.me). | ||
You should hear from us within a week, though we aim to release patches as quickly as possible. The last two security patches were released within a few hours of being reported privately to us. |