expressjs / expressjs/security-wg

Time for a bounty program?

Open
#64 12 comments 1 reaction 1 assignee Claimed by @UlisesGascon View on GitHub
Dominant language
No language data
Stars
17
Forks
12
Avg merge
1m
Merged PRs (30d)
1

Description

In the past we had mention the option to run a bounty program ([ref](https://github.com/expressjs/security-wg/issues/7)) to engage with more security researches. Also other Open Source project within the foundation engaged with this programs too.

I was thinking that Hacker One (H1) is a great option for us as they have a [Community Edition](https://www.hackerone.com/company/open-source-community) that fits well with our approach.

Even if we don't have enough economical resources to reward for bounties this program will provide reputation to the researches.

I already sent them an email to see if they want to accept us in their program (exploring not confirming).

Note that this was part of the objectives that we set for the milestone 3 in STF:

> We will also explore the possibility of joining a bug bounty platform to encourage more community engagement in reporting bugs and vulnerabilities, thereby enhancing the overall security of the project.

It also worth mention that we are actively working on defining better the process on how to handle security reports (https://github.com/expressjs/security-wg/pull/56) and manage expectations (https://github.com/expressjs/.github/pull/15)

WDYT @expressjs/express-tc @expressjs/security-wg @expressjs/security-triage?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.