Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,13 @@ you informed of the progress being made towards a fix and full announcement,
and may ask for additional information or guidance surrounding the reported
issue.

If you do not receive an acknowledgement of your report within 6 business
days, or if you cannot find a private security contact for the project, you
may escalate to the OpenJS Foundation CNA at `[email protected]`.

If the project acknowledges your report but does not provide any further
response or engagement within 14 days, escalation is also appropriate.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is fine but what does escalation entail?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Escalation means contacting the OpenJS Foundation CNA if the Node.js security team is unresponsive. The CNA can ensure your report is acknowledged, help coordinate disclosure, and assign a CVE if necessary. Escalation does not bypass the normal process or guarantee a faster fix. It is a safeguard to ensure reports are properly handled.


### Node.js bug bounty program

The Node.js project engages in an official bug bounty program for security
Expand Down
Loading