docs: added responsible disclosure and hall of fame

This commit is contained in:
Mehul Mohan
2020-02-06 18:14:20 +05:30
committed by Mrugesh Mohapatra
parent f4fbe1d97c
commit 158188924b
3 changed files with 21 additions and 12 deletions

5
HoF.md Normal file
View File

@ -0,0 +1,5 @@
# Responsible Disclosure
freeCodeCamp appreciates any responsible disclosure of vulnerabilities which might impact the integrity of the platform or the users associated with it. Although we do not offer any bounties or swags at the moment, we'll be happy to list your name in our Hall of Fame list below:
1. Mehul Mohan from [codedamn](https://codedamn.com) ([@mehulmpt](https://twitter.com/mehulmpt)) - [Vulnerability Fix](https://github.com/freeCodeCamp/freeCodeCamp/blob/bb5a9e815313f1f7c91338e171bfe5acb8f3e346/client/src/components/Flash/index.js)

View File

@ -13,14 +13,13 @@ Our full-stack web development curriculum is completely free and self-paced. We
## Table of Contents ## Table of Contents
* [Certifications](#certifications) - [Certifications](#certifications)
* [The Learning Platform](#the-learning-platform) - [The Learning Platform](#the-learning-platform)
* [Reporting Bugs and Issues](#reporting-bugs-and-issues) - [Reporting Bugs and Issues](#reporting-bugs-and-issues)
* [Reporting Security Issues](#reporting-security-issues) - [Reporting Security Issues and Responsible Disclosure](#reporting-security-issues-and-responsible-disclosure)
* [Contributing](#contributing) - [Contributing](#contributing)
* [Platform, Build and Deployment Status](#platform-build-and-deployment-status) - [Platform, Build and Deployment Status](#platform-build-and-deployment-status)
* [License](#license) - [License](#license)
### Certifications ### Certifications
@ -128,13 +127,16 @@ Our community also has:
> ### [Join our community here](https://www.freecodecamp.org/signin). > ### [Join our community here](https://www.freecodecamp.org/signin).
### Reporting Bugs and Issues ### Reporting Bugs and Issues
If you think you've found a bug, first read the [how to report a bug](https://www.freecodecamp.org/forum/t/how-to-report-a-bug/19543) article and follow its instructions. If you think you've found a bug, first read the [how to report a bug](https://www.freecodecamp.org/forum/t/how-to-report-a-bug/19543) article and follow its instructions.
If you're confident it's a new bug and have confirmed that someone else is facing the same issue, go ahead and create a new GitHub issue. Be sure to include as much information as possible so we can reproduce the bug. If you're confident it's a new bug and have confirmed that someone else is facing the same issue, go ahead and create a new GitHub issue. Be sure to include as much information as possible so we can reproduce the bug.
### Reporting Security Issues ### Reporting Security Issues and Responsible Disclosure
If you think you have found a vulnerability, please report responsibly. Don't create GitHub issues for security issues. Instead, please send an email to `security@freecodecamp.org` and we'll look into it immediately. If you think you have found a vulnerability, *please report responsibly*. Don't create GitHub issues for security issues. Instead, please send an email to `security@freecodecamp.org` and we'll look into it immediately.
We appreciate any responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](HoF.md) list.
### Contributing ### Contributing

View File

@ -12,6 +12,8 @@ This document outlines our security policy for the codebase, and how to report v
## Reporting a Vulnerability ## Reporting a Vulnerability
Security issues should be emailed to security@freecodecamp.org, please do not create a public GitHub issue. If you think you have found a vulnerability, *please report responsibly*. Don't create GitHub issues for security issues. Instead, please send an email to `security@freecodecamp.org` and we'll look into it immediately.
We appreciate any responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](HoF.md) list.
Ensure that you are using the **latest**, **stable** and **updated** version of the Operating System and Web Browser available to you on your machine. Ensure that you are using the **latest**, **stable** and **updated** version of the Operating System and Web Browser available to you on your machine.