| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 8abd54f commit 236d7ee
1 file changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -348,6 +348,21 @@ Security notifications will be distributed via the following methods. | |||
| 348 | 348 | * <https://groups.google.com/group/nodejs-sec> | |
| 349 | 349 | * <https://nodejs.org/en/blog/vulnerability> | |
| 350 | 350 | ||
| 351 | + ### CVE publication timeline | ||
| 352 | + | ||
| 353 | + When security releases are published, there is a built-in delay before the | ||
| 354 | + corresponding CVEs are publicly disclosed. This delay occurs because: | ||
| 355 | + | ||
| 356 | + 1. After the security release, we request the vulnerability reporter to disclose | ||
| 357 | + the details on HackerOne. | ||
| 358 | + 2. If the reporter does not disclose within one day, we proceed with forced | ||
| 359 | + disclosure to publish the CVEs. | ||
| 360 | + 3. The disclosure then goes through HackerOne's approval process before the CVEs | ||
| 361 | + become publicly available. | ||
| 362 | + | ||
| 363 | + As a result, CVEs may not be immediately available when security releases are | ||
| 364 | + published, but will typically be disclosed within a few days of the release. | ||
| 365 | + | ||
| 351 | 366 | ## Comments on this policy | |
| 352 | 367 | ||
| 353 | 368 | If you have suggestions on how this process could be improved, please visit | |
| Back | FazBrowse Home | New Git URL |
0 commit comments