Settings

Theme

Node.js Security Bug Bounty Program Paused Due to Loss of Funding

nodejs.org

4 points by tjwds 2 months ago · 2 comments

Reader

GeoSys 2 months ago

That's pretty bad ... So many Fortune 500 companies using Node couldn't fork some spare change to keep themselves (and us) safe ...

  • benoau 2 months ago

    It's not that they're out of funding per-se:

    > The discovery landscape is changing. AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted. We have a responsibility to the community to ensure this program effectively accomplishes its ambitious dual purpose: discovery and remediation. Accordingly, we are pausing submissions while we consider the structure and incentives needed to further these goals.

    https://hackerone.com/ibb?type=team

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection