You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

33 lines
1.5 KiB

7 years ago
  1. # Security Guidelines
  2. Please contact us directly at **security@3rd-Eden.com** for any bug that might
  3. impact the security of this project. Please prefix the subject of your email
  4. with `[security]` in lowercase and square brackets. Our email filters will
  5. automatically prevent these messages from being moved to our spam box.
  6. You will receive an acknowledgement of your report within **24 hours**.
  7. All emails that do not include security vulnerabilities will be removed and
  8. blocked instantly.
  9. ## Exceptions
  10. If you do not receive an acknowledgement within the said time frame please give
  11. us the benefit of the doubt as it's possible that we haven't seen it yet. In
  12. this case please send us a message **without details** using one of the
  13. following methods:
  14. - Contact the lead developers of this project on their personal e-mails. You
  15. can find the e-mails in the git logs, for example using the following command:
  16. `git --no-pager show -s --format='%an <%ae>' <gitsha>` where `<gitsha>` is the
  17. SHA1 of their latest commit in the project.
  18. - Create a GitHub issue stating contact details and the severity of the issue.
  19. Once we have acknowledged receipt of your report and confirmed the bug
  20. ourselves we will work with you to fix the vulnerability and publicly acknowledge
  21. your responsible disclosure, if you wish. In addition to that we will report
  22. all vulnerabilities to the [Node Security Project](https://nodesecurity.io/).
  23. ## History
  24. 04 Jan 2016: [Buffer vulnerablity](https://github.com/websockets/ws/releases/tag/1.0.1)