Skip to content
This repository has been archived by the owner on Jul 19, 2022. It is now read-only.

Security: gluwa/creditcoin-legacy-shared

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please send a detailed mail to security@gluwa.com to request to be invited in the VDP program in Bugcrowd.

It is recommended to send the report to security@gluwa.com (and obviously not to discuss the issue anywhere else).

Examples for details to include:

  • Ideally a short description (or a script) to demonstrate an exploit.
  • The affected platforms and scenarios (the vulnerability might only affect setups with case-sensitive file systems, for example).
  • The name and affiliation of the security researchers who are involved in the discovery, if any.
  • Whether the vulnerability has already been disclosed.
  • How long an embargo would be required to be safe.

Vulnerability Disclosure Program

Our vulnerability disclosure program is hosted through Bugcrowd and is in a closed state, if you wish to be included in the program send an email with your username to security@gluwa.com requesting an invitation to the bounty program.

There aren’t any published security advisories