-
Notifications
You must be signed in to change notification settings - Fork 55
docs: add SECURITY.md with vulnerability reporting guidelines #480
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
🛡️ Immunefi PR ReviewsWe noticed that your project isn't set up for automatic code reviews. If you'd like this PR reviewed by the Immunefi team, you can request it manually using the link below: Once submitted, we'll take care of assigning a reviewer and follow up here. |
|
Nice one man |
duncancmt
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
line wrap to 80 columns
|
|
||
| 0x hosts a bug bounty program on Immunefi: | ||
|
|
||
| **https://immunefi.com/bug-bounty/0x** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
please format this as a link
| ### Alternative Contact | ||
|
|
||
| For security issues that may not qualify for the bug bounty, you can also contact: | ||
|
|
||
| **Email**: [security@0x.org](mailto:security@0x.org) | ||
|
|
||
| When reporting via email, please include: | ||
| - A detailed description of the vulnerability | ||
| - Steps to reproduce the issue | ||
| - Potential impact assessment | ||
| - A proof-of-concept exploit (if possible) | ||
|
|
||
| Use the subject line: **"BUG BOUNTY"** or **"SECURITY VULNERABILITY"** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
reporting vulnerabilities over email is discouraged. please remove this section
| ## Security Audits | ||
|
|
||
| 0x Settler has undergone security audits. Audit reports can be found in the repository documentation. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
link to the audits directory
| Please do NOT: | ||
| - Open a public GitHub issue for security vulnerabilities | ||
| - Disclose the vulnerability publicly before it has been addressed | ||
| - Exploit the vulnerability beyond what is necessary to demonstrate it |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
no. exploiting vulnerabilities is blackhat shit, even as a demonstration
| ## Supported Versions | ||
|
|
||
| | Version | Supported | | ||
| | ------- | ------------------ | | ||
| | Latest | :white_check_mark: | | ||
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this is pointless. remove it.
| ## Security Contact | ||
|
|
||
| For general security inquiries: [security@0x.org](mailto:security@0x.org) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
remove this.
Summary
This PR adds a
SECURITY.mdfile to consolidate security reporting guidelines.Changes
Added
SECURITY.mdwith:Motivation
Security information is currently spread across:
sh/initial_description_*.mdfiles (email contact)A root-level
SECURITY.mdfile: