-
-
Notifications
You must be signed in to change notification settings - Fork 132
Description
As discussed in last WG meeting and based on @jasnell issue regarding an early disclosure program for vulnerabilities in Node.js core. We would like to collect opinions from potential users of such initiative:
In other term, if you or an organization you are involved with would want to have access of such an early disclosure program, please explain here what you would need such program to be.
For instance, a cloud provider might want to have access to patched binaries of Node.js before their public disclosure in order to provide protection to their clients as soon as possible.
Please let us know how we can build something relevant for you.
Also, please feel free to advertise this issue to anyone who might be interested in providing feedback on this topic.