-
Notifications
You must be signed in to change notification settings - Fork 447
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Showing
1 changed file
with
19 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
# Tutor Ethical Vulnerability Disclosure Policy | ||
|
||
|
||
## Reporting a Vulnerability | ||
|
||
To ensure the health of the codebase and the larger Open edX and Tutor communities, please do not create GitHub issues for a security vulnerability. Report any security vulnerabilities or concerns by sending an email to [[email protected]](mailto:[email protected]). To ensure a timely triage and fix of the security issue, include as many details you can when reporting the vulnerability. Some pieces of information to consider: | ||
|
||
* The nature of the vulnerability, e.g. | ||
* Authentication and Authorization | ||
* Data Integrity and Confidentiality | ||
* Security Configurations | ||
* Third-party dependencies | ||
* The impact of the security risk | ||
* A detailed description of the steps necessary to reproduce the issue | ||
* The links to the vulnerable code | ||
* The links to third-party libraries/packages if the vulnerability is present in such a dependency. | ||
|
||
## Bug Bounty | ||
Edly/Tutor does not offer a bug bounty for reported vulnerabilities. |