mirror of
https://github.com/curl/curl.git
synced 2026-07-24 03:07:17 +03:00
BUG-BOUNTY.md: clarify the third party situation
We do not pay bounties for problems in other libraries. Closes #13560
This commit is contained in:
parent
22d8ce1970
commit
87b6fe1695
1 changed files with 7 additions and 0 deletions
|
|
@ -67,6 +67,13 @@ infrastructure.
|
|||
The curl security team is the sole arbiter if a reported flaw is subject to a
|
||||
bounty or not.
|
||||
|
||||
## Third parties
|
||||
|
||||
The curl bug bounty does not cover flaws in third party dependencies
|
||||
(libraries) used by curl or libcurl. If the bug triggers because of curl
|
||||
behaving wrongly or abusing a third party dependency, the problem is rather in
|
||||
curl and not in the dependency and then the bounty might cover the problem.
|
||||
|
||||
## How are vulnerabilities graded?
|
||||
|
||||
The grading of each reported vulnerability that makes a reward claim is
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue