blog: clarify contact method for low signal researchers#8613
blog: clarify contact method for low signal researchers#8613UlisesGascon wants to merge 1 commit intonodejs:mainfrom
Conversation
Signed-off-by: Ulises Gascón <ulisesgascongonzalez@gmail.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
👋 Codeowner Review RequestThe following codeowners have been identified for the changed files: Team reviewers: @nodejs/releasers Please review the changes when you have a chance. Thank you! 🙏 |
There was a problem hiding this comment.
Pull request overview
Updates an existing Node.js blog announcement to clarify how low-signal security researchers should contact the security team, making the guidance more actionable.
Changes:
- Specifies the OpenJS Foundation Slack channel (
#nodejs-security-wg) to use for contacting the security team when below the HackerOne Signal threshold.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8613 +/- ##
==========================================
- Coverage 74.95% 74.89% -0.06%
==========================================
Files 103 103
Lines 9063 9063
Branches 312 313 +1
==========================================
- Hits 6793 6788 -5
- Misses 2268 2273 +5
Partials 2 2 ☔ View full report in Codecov by Sentry. |
| - **New researchers or researchers with [signal][Signal] >= 1.0**: You can continue reporting vulnerabilities through HackerOne as usual | ||
| - **Those below the threshold**: You can still reach the security team through the | ||
| [OpenJS Foundation Slack](https://slack-invite.openjsf.org/). Contact us there to discuss potential | ||
| [OpenJS Foundation Slack](https://slack-invite.openjsf.org/) (channel: `#nodejs-security-wg`). Contact us there to discuss potential |
There was a problem hiding this comment.
I guess we don't want them to disclose that in a public channel, instead we prefer to contact security release stewards directly.
Ref: https://openjs-foundation.slack.com/archives/C03Q9MS3KFB/p1770571419056129