Skip to content

[RFC] Early disclosure program  #68

@vdeturckheim

Description

@vdeturckheim

As discussed in last WG meeting and based on @jasnell issue regarding an early disclosure program for vulnerabilities in Node.js core. We would like to collect opinions from potential users of such initiative:

In other term, if you or an organization you are involved with would want to have access of such an early disclosure program, please explain here what you would need such program to be.

For instance, a cloud provider might want to have access to patched binaries of Node.js before their public disclosure in order to provide protection to their clients as soon as possible.

Please let us know how we can build something relevant for you.

Also, please feel free to advertise this issue to anyone who might be interested in providing feedback on this topic.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions