Skip to content

Commit 34ada34

Browse files
authored
doc: add governance for LFX Crowdfunding account (#1313)
* doc: add governance for LFX Crowdfunding account Signed-off-by: Michael Dawson <mdawson@devrus.com>
1 parent 1afe6f5 commit 34ada34

File tree

1 file changed

+34
-0
lines changed

1 file changed

+34
-0
lines changed

Nodejs-Bug-Bounty-Security-Fund.md

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# Node.js Bug Bounty/Security Fund
2+
3+
The TSC maintains a Linux Foundation Crowdfunding account to accept
4+
the project's share of bug bounties paid out by the
5+
[Hackerone](https://www.hackerone.com/) bug bounty program.
6+
7+
The funds are to be used
8+
to encourage contributions to the project with respect to
9+
security and in particular the handling of vulnearabilities.
10+
11+
This document outlines the use this account.
12+
13+
## Account details
14+
15+
The [account](https://crowdfunding.lfx.linuxfoundation.org/initiative/578a541a-4e7e-47a2-99b9-6cbf49b00c20)
16+
is associated with and Linux Foundation Crowdfunding account. The user id and password
17+
are shared with TSC members through 1password.
18+
19+
## Disbursements
20+
21+
Potential disbursements will be agreed through TSC discussion
22+
and before approval, documented in an issue in the
23+
[TSC repository](https://github.com/nodejs/TSC). The disbursement
24+
is considered approved once TSC consensus in the issue has
25+
been reached.
26+
27+
Once a disbursement has been approved the recipient will open
28+
a request through the LFX account in the amout approved.
29+
30+
The Chair of the Technical Steering committee will then
31+
"push the required buttons" in the LFX account to initiate
32+
the payout in accordance with the agreement reached in the
33+
TSC issue and if possible including a reference to the issue
34+
in the TSC repository.

0 commit comments

Comments
 (0)