Bug Bounty program coming soon! 🏁 #52
Replies: 2 comments
-
Before we start with a bug bounty program it's necessary to prepare on the most important topics: Scope
Payout
Workflow
Transparency
|
Beta Was this translation helpful? Give feedback.
-
Some inputs after discussion with @RoKrish14 and @BANANAS1337.
Starting with a couple of repositories that crucial to the ecosystem, e.g. EDC and BDPM. Prioritization together with Tractus-X project leads.
We will monitor the bug bounty program results and tend to add additional repositories to the scope on a monthly basis after successful pre-check.
Handle incoming reports on the bug bounty program provider platform first and after successful validation by sig-security member we put them into the regular workflow for reporting a vulnerability according to EF Vulnerability Reporting Policy in the affected repository.
If it's not possible to evaluate on our own that it is a valid issue, we report them as well according the regular workflow for reporting a vulnerability according to EF Vulnerability Reporting Policy in the affected repository. |
Beta Was this translation helpful? Give feedback.
-
Stay tuned!
We will soon inform you about the bug bounty initiative
Beta Was this translation helpful? Give feedback.
All reactions