summaryrefslogtreecommitdiff
path: root/docs/SECURITY-PROCESS.md
Commit message (Collapse)AuthorAgeFilesLines
* SECURITY-PROCESS: fix links [ci skip]Daniel Stenberg2019-05-111-4/+4
|
* docs: minor polish to the bug bounty / security docsReed Loden2019-04-291-3/+3
| | | | Closes #3811
* docs/BUG-BOUNTY: bug bounty time [skip ci]Daniel Stenberg2019-04-221-27/+24
| | | | | | | | | | Introducing the curl bug bounty program on hackerone. We now recommend filing security issues directly in the hackerone ticket system which only is readable to curl security team members. Assisted-by: Daniel Gustafsson Closes #3488
* SECURITY-PROCESS: bountygraph shuts downDaniel Stenberg2018-11-301-13/+9
| | | | | | This backpedals back the documents to the state before bountygraph. Closes #3311
* docs/SECURITY-PROCESS: the hackerone IBB program drops curlDaniel Stenberg2018-10-171-14/+0
| | | | ... now there's only BountyGraph.
* SECURITY-PROCESS: make links into hyperlinksDaniel Gustafsson2018-10-031-3/+4
| | | | | | | | | Use proper Markdown hyperlink format for the Bountygraph links in order for the generated website page to be more user friendly. Also link to the sponsors to give them a little extra credit. Closes #3082 Reviewed-by: Daniel Stenberg <daniel@haxx.se>
* SECURITY-PROCESS: mention the bountygraph program [ci skip]Daniel Stenberg2018-09-221-4/+21
| | | | Closes #3032
* secure Openwall URLsViktor Szakats2018-09-141-1/+1
|
* docs/SECURITY-PROCESS: now we name the files after the CVE idDaniel Stenberg2018-08-201-7/+2
|
* docs/SECURITY-PROCESS: mention bounty, drop pre-notifyDaniel Stenberg2018-07-121-12/+13
| | | | | | + The hackerone bounty and its process - We don't and can't handle pre-notification
* SECURITY-PROCESS: mention how we write/add advisoriesDaniel Stenberg2018-03-141-3/+26
|
* docs/SECURITY.md -> docs/SECURITY-PROCESS.mdDaniel Stenberg2018-03-111-0/+116