Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

As someone submitting security vulnerabilities, I want up-to-date information about how to do so #49

Closed
1 task
afeld opened this issue Jul 19, 2019 · 7 comments
Assignees

Comments

@afeld
Copy link
Contributor

afeld commented Jul 19, 2019

Currently, we have a number of paths/documentation:

There is definitely overlap - we should consolidate.

cc #31

@cryptofilegsa

This comment has been minimized.

@afeld
Copy link
Contributor Author

afeld commented Aug 6, 2019

  • Clarify the SLAs

@adborden

This comment has been minimized.

@afeld afeld changed the title As someone submitting/triaging security vulnerabilities, I want up-to-date information about how to do so As someone submitting security vulnerabilities, I want up-to-date information about how to do so Aug 29, 2019
@afeld
Copy link
Contributor Author

afeld commented Aug 29, 2019

Clarified this issue to be about incident reporting, while #77 is about triaging and response.

@adborden
Copy link
Contributor

https://github.com/18F/bug-bounty is listed as "OUT OF DATE" with a link to this issue. Since bug-bounty is about documenting how to administer the TTS Bug Bounty program, I'm not sure why this issue is related, or why bug-bounty is out of date.

@adborden
Copy link
Contributor

What was the resolution here? https://github.com/18F/bug-bounty still links to this issue. Is there a new doc that should be linked instead?

@its-a-lisa-at-work
Copy link
Contributor

The Public Disclosures of Vulnerabilities site on TTS was updated -- if there are other things that you think need to be addressed, please let me know and we'll create a new card

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants