docs/BUG-BOUNTY: bug bounty time [skip ci]

Introducing the curl bug bounty program on hackerone. We now recommend
filing security issues directly in the hackerone ticket system which
only is readable to curl security team members.

Assisted-by: Daniel Gustafsson

Closes #3488
This commit is contained in:
Daniel Stenberg 2019-04-20 12:19:47 +02:00
parent eb84ca3ea8
commit 10e4dd6a7b
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
6 changed files with 130 additions and 32 deletions

View file

@ -1,5 +1,6 @@
<!-- Only file bugs here! Ask questions on the mailing list https://curl.haxx.se/mail/
Do not file security vulnerabilities here, e-mail curl-security at haxx.se
<!-- Only file bugs here! Ask questions on the mailing lists https://curl.haxx.se/mail/
SECURITY RELATED? Post it here: https://hackerone.com/curl
There are collections of known issues to be aware of:
https://curl.haxx.se/docs/knownbugs.html