Skip to content

Commit 73b63f4

Browse files
authored
doc: add procedure when CVEs don't get published
This was the workaround provided by HackerOne team
1 parent d42949e commit 73b63f4

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

doc/contributing/security-release-process.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -200,6 +200,11 @@ out a better way, forward the email you receive to
200200
* Request publication of [H1 CVE requests][]
201201
* (Check that the "Version Fixed" field in the CVE is correct, and provide
202202
links to the release blogs in the "Public Reference" section)
203+
* In case the reporter doesn't accept the disclosure follow this process:
204+
* Remove the original report reference within the reference text box and
205+
insert the public URL you would like to be attached to this CVE.
206+
* Then uncheck the Public Disclosure on HackerOne box at the bottom of the page.
207+
![image (4)](https://github.com/RafaelGSS/node/assets/26234614/98009250-c538-4e36-895f-6d2cde4cb5c1)
203208

204209
* [ ] PR machine-readable JSON descriptions of the vulnerabilities to the
205210
[core](https://github.com/nodejs/security-wg/tree/HEAD/vuln/core)

0 commit comments

Comments
 (0)