Blog: New HackerOne Signal Requirement for reports#8658
Blog: New HackerOne Signal Requirement for reports#8658
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
👋 Codeowner Review RequestThe following codeowners have been identified for the changed files: Team reviewers: @nodejs/nodejs-website Please review the changes when you have a chance. Thank you! 🙏 |
There was a problem hiding this comment.
Pull request overview
This PR adds important documentation about HackerOne Signal requirements for submitting security reports to Node.js. The change clarifies that a minimum Signal score of 1.0 is required to report through HackerOne, and provides an alternative contact method via the OpenJS Foundation Slack for users below this threshold.
Changes:
- Added a note explaining the HackerOne Signal score requirement (minimum 1.0) for security report submissions
- Provided alternative contact method for users below the threshold via OpenJS Foundation Slack
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8658 +/- ##
==========================================
- Coverage 75.12% 75.08% -0.05%
==========================================
Files 104 104
Lines 9098 9098
Branches 314 315 +1
==========================================
- Hits 6835 6831 -4
- Misses 2261 2265 +4
Partials 2 2 ☔ View full report in Codecov by Sentry. |
📦 Build Size ComparisonSummary
Changes➕ Added Assets (1)
➖ Removed Assets (1)
|
|
Lighthouse Results
|
PTAL @nodejs/security-triage