Skip to content

Time for a bounty program? #345

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
UlisesGascon opened this issue Mar 7, 2025 · 7 comments
Open

Time for a bounty program? #345

UlisesGascon opened this issue Mar 7, 2025 · 7 comments
Assignees
Labels
discuss meeting top priority Issues which the TC deem our current highest priorities for the project

Comments

@UlisesGascon
Copy link
Member

In the past we had mention the option to run a bounty program (ref) to engage with more security researches. Also other Open Source project within the foundation engaged with this programs too.

I was thinking that Hacker One (H1) is a great option for us as they have a Community Edition that fits well with our approach.

Even if we don't have enough economical resources to reward for bounties this program will provide reputation to the researches.

I already sent them an email to see if they want to accept us in their program (exploring not confirming).

Note that this was part of the objectives that we set for the milestone 3 in STF:

We will also explore the possibility of joining a bug bounty platform to encourage more community engagement in reporting bugs and vulnerabilities, thereby enhancing the overall security of the project.

It also worth mention that we are actively working on defining better the process on how to handle security reports (expressjs/security-wg#56) and manage expectations (expressjs/.github#15)

WDYT @expressjs/express-tc @expressjs/security-wg @expressjs/security-triage?

@UlisesGascon UlisesGascon self-assigned this Mar 7, 2025
@UlisesGascon UlisesGascon added meeting discuss top priority Issues which the TC deem our current highest priorities for the project tc agenda labels Mar 7, 2025
@bjohansebas
Copy link
Member

+1, although it would mean that we would no longer use GitHub in the future to report security issues (see expressjs/security-wg#30), right?

@UlisesGascon
Copy link
Member Author

UlisesGascon commented Mar 8, 2025

+1, although it would mean that we would no longer use GitHub in the future to report security issues (see expressjs/security-wg#30), right?

Not really, We include it as a valid way to report vulnerabilities in https://github.com/expressjs/.github/blob/master/SECURITY.md#reporting-a-bug. I will create a PR to clarify that See: expressjs/.github#16

@0xAverageUser
Copy link

@UlisesGascon I think might be worth reaching out to [email protected] to get this sponsored by the Internet Bug Bounty Program

@bjohansebas
Copy link
Member

bjohansebas commented Mar 16, 2025

@UlisesGascon I think might be worth reaching out to [email protected] to get this sponsored by the Internet Bug Bounty Program

I see that several projects from the foundation are included here, I think it's great to request inclusion. (https://hackerone.com/ibb/policy_scopes)

@UlisesGascon
Copy link
Member Author

@marco-ippolito @RafaelGSS can you tell us about your experience in the program with Node.js? How was your experience so far (day to day, reports quality, tricks...)? 🙏

@wesleytodd
Copy link
Member

I don't see it mentioned here, but it looks like the STF also has a program for bug bounties which we should assess. I don't have a strong opinion in general here, but just wanted to drop this note since it was only mentioned so far in an email with @UlisesGascon and I on it.

@wesleytodd
Copy link
Member

As discussed on last week's working session, this discussion is moving to the @expressjs/security-wg. So removing the agenda label.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
discuss meeting top priority Issues which the TC deem our current highest priorities for the project
Projects
None yet
Development

No branches or pull requests

4 participants