File tree Expand file tree Collapse file tree 1 file changed +34
-0
lines changed
Expand file tree Collapse file tree 1 file changed +34
-0
lines changed Original file line number Diff line number Diff line change 1+ # Node.js Bug Bounty/Security Fund
2+
3+ The TSC maintains a Linux Foundation Crowdfunding account to accept
4+ the project's share of bug bounties paid out by the
5+ [ Hackerone] ( https://www.hackerone.com/ ) bug bounty program.
6+
7+ The funds are to be used
8+ to encourage contributions to the project with respect to
9+ security and in particular the handling of vulnearabilities.
10+
11+ This document outlines the use this account.
12+
13+ ## Account details
14+
15+ The [ account] ( https://crowdfunding.lfx.linuxfoundation.org/initiative/578a541a-4e7e-47a2-99b9-6cbf49b00c20 )
16+ is associated with and Linux Foundation Crowdfunding account. The user id and password
17+ are shared with TSC members through 1password.
18+
19+ ## Disbursements
20+
21+ Potential disbursements will be agreed through TSC discussion
22+ and before approval, documented in an issue in the
23+ [ TSC repository] ( https://github.com/nodejs/TSC ) . The disbursement
24+ is considered approved once TSC consensus in the issue has
25+ been reached.
26+
27+ Once a disbursement has been approved the recipient will open
28+ a request through the LFX account in the amout approved.
29+
30+ The Chair of the Technical Steering committee will then
31+ "push the required buttons" in the LFX account to initiate
32+ the payout in accordance with the agreement reached in the
33+ TSC issue and if possible including a reference to the issue
34+ in the TSC repository.
You can’t perform that action at this time.
0 commit comments