Skip to content

Security: bandungdevcom/bandungdev.com

Security

SECURITY.md

Reporting Security Issues

The BandungDev team and community need to learn and take security bugs in BandungDev seriously.

We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.

To report a security issue, please use the GitHub Security Advisory "Report a Vulnerability" tab.

The BandungDev team will send a response indicating the next steps in handling your report. After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.

Report security bugs in third-party modules to the person or team maintaining the module.

In case it's caused by JavaScript package, you can also report a vulnerability through the npm contact form by selecting "I'm reporting a security vulnerability".

The BandungDev Security Notification Process

We currently still plan to set the security notification process. At the moment, feel free to inform on BandungDev Telegram group. One or more of the admins will respond from there.

But this might take an inspiration from Electron's notes:

For context on security notification process, please see the Notifications section of the Security WG's Membership and Notifications Governance document.

There aren’t any published security advisories