You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Aug 23, 2022. It is now read-only.
Give people a place to notify us privately when they find security issues. This could be as simple as an email address, but let's be explicit about it.
The text was updated successfully, but these errors were encountered:
Yes! This should be mandatory for any project, open source or not. Having said that, one of the most used tools for ethical hacking and bounties is HackerOne. It's used by big enterprises like: Discourse, Starbucks and Spotify all around the world. Fortunate for us, they have a community edition (free).
I think the learning value here is derived from using this third-party high-end bug bounty tool which could (or should ;-)) be applied for customers with an open to public platform.
What is your opinion about using a tool like this?
Oh If we're eligible I'm all for it :-) Certainly an area where we could learn from using a good high-end tool. I have applied for a community edition account. And now... we wait!
Give people a place to notify us privately when they find security issues. This could be as simple as an email address, but let's be explicit about it.
The text was updated successfully, but these errors were encountered: