Skip to content
Merged
Changes from 1 commit
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
1461f86
docs: add document to handle security reports
UlisesGascon Mar 5, 2025
c30511c
docs: add Security Report Handling Flowchart
UlisesGascon Mar 5, 2025
1a9042a
docs: add roles
UlisesGascon Mar 7, 2025
7aac07b
docs: add runbook
UlisesGascon Mar 7, 2025
03d7b60
Update docs/handle_security_reports.md
UlisesGascon Mar 8, 2025
dba71a6
Update docs/handle_security_reports.md
UlisesGascon Mar 8, 2025
99b4102
Update docs/handle_security_reports.md
UlisesGascon Mar 8, 2025
054ab8a
fix: format issues
UlisesGascon Mar 8, 2025
707c04d
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
eec7b04
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
de83da8
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
e88d94d
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
ee83fa1
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
799e888
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
315b02c
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
183adc6
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
014a4b1
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
fbc2d2c
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
fa6bf1b
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
6bb6700
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
0241b7c
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
2544711
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
38b6532
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
8c09fbb
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update docs/handle_security_reports.md
Co-authored-by: Sebastian Beltran <bjohansebas@gmail.com>
  • Loading branch information
UlisesGascon and bjohansebas authored Mar 8, 2025
commit 03d7b60d5acea55af0faaf59f2ea1813dd8e485f
2 changes: 1 addition & 1 deletion docs/handle_security_reports.md
Original file line number Diff line number Diff line change
Expand Up @@ -129,7 +129,7 @@ Ideally, the report must contain **clear and detailed information** like (Affect
* [Open a ticket with GitHub](https://support.github.com/contact) to delete the pull request using Expressjs (team) as the account organization.
* Open a new issue in the public repository with the title `FYI - pull request deleted #YYYY`. Include an explanation for the user:
> FYI @xxxx we asked GitHub to delete your pull request while we work on releases in private.
* Update the the team in the slack channel #express-security-triage`.
* Update the team in the slack channel #express-security-triage`.

1.2.2 In the case that the report is made public in a different channel that we don't own/control is expected from the TC to find ways (when possible) to mitigate this by treying to remove the report from public view (reporting to support, asking the reporter to remove the report, etc...).

Expand Down