Commit 2eefa47
authored
Update SECURITY.md to reflect bug bounty program (#169)
## Summary
Updates `SECURITY.md` to direct security reporters to LaunchDarkly's Bug
Bounty program.
## Changes
- Security issues should be reported through the [Bug Bounty
program](https://bugcrowd.com/engagements/launchdarkly-mbb-og) rather
than via GitHub Issues or PRs
- Clarifies that valid security issues may be eligible for a bounty
This is a cross-repository update to standardize security reporting
instructions across LaunchDarkly repositories.
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Low Risk**
> Documentation-only change to security reporting instructions; no
application or infrastructure code is modified.
>
> **Overview**
> **`SECURITY.md`** is updated so security reporting matches
LaunchDarkly’s current process across repos.
>
> The doc now **boldly warns** not to file GitHub Issues or PRs for
vulnerabilities, with clearer rationale about public exposure. Reporting
is directed to the **Bugcrowd** [Bug Bounty
program](https://bugcrowd.com/engagements/launchdarkly-mbb-og) instead
of the previous **HackerOne** link, and a line is added asking reporters
**not to contact LaunchDarkly staff directly**.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
ee5537f. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->1 parent 5f605d4 commit 2eefa47
1 file changed
Lines changed: 5 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
| 4 | + | |
4 | 5 | | |
5 | | - | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
0 commit comments