| @@ -1,0 +1,47 @@ | ||
| 1 | +# Security Policy | |
| 2 | + | |
| 3 | +Full details of the Automattic Security Policy can be found on [automattic.com](https://automattic.com/security/). | |
| 4 | + | |
| 5 | +## Supported Versions | |
| 6 | + | |
| 7 | +Generally, only the latest version of Jetpack and its associated plugins have continued support. If a critical vulnerability is found in the current version of a plugin, we may opt to backport any patches to previous versions. | |
| 8 | + | |
| 9 | +## Reporting a Vulnerability | |
| 10 | + | |
| 11 | +Our HackerOne program covers the below plugin software, as well as a variety of related projects and infrastructure: | |
| 12 | + | |
| 13 | +* [Jetpack](https://jetpack.com/) | |
| 14 | +* Jetpack Backup | |
| 15 | +* Jetpack Boost | |
| 16 | +* Jetpack Protect | |
| 17 | +* Jetpack Search | |
| 18 | +* Jetpack Social | |
| 19 | +* Jetpack Stats | |
| 20 | +* Jetpack VideoPress | |
| 21 | + | |
| 22 | +**For responsible disclosure of security issues and to be eligible for our bug bounty program, please submit your report via the [HackerOne](https://hackerone.com/automattic) portal.** | |
| 23 | + | |
| 24 | +Our most critical targets are: | |
| 25 | + | |
| 26 | +* Jetpack and the Jetpack composer packages (all within this repo) | |
| 27 | +* Jetpack.com -- the primary marketing site. | |
| 28 | +* cloud.jetpack.com -- a management site. | |
| 29 | +* wordpress.com -- the shared management site for both Jetpack and WordPress.com sites. | |
| 30 | + | |
| 31 | +For more targets, see the `In Scope` section on [HackerOne](https://hackerone.com/automattic). | |
| 32 | + | |
| 33 | +_Please note that the **WordPress software is a separate entity** from Automattic. Please report vulnerabilities for WordPress through [the WordPress Foundation's HackerOne page](https://hackerone.com/wordpress)._ | |
| 34 | + | |
| 35 | +## Guidelines | |
| 36 | + | |
| 37 | +We're committed to working with security researchers to resolve the vulnerabilities they discover. You can help us by following these guidelines: | |
| 38 | + | |
| 39 | +* Follow [HackerOne's disclosure guidelines](https://www.hackerone.com/disclosure-guidelines). | |
| 40 | +* Pen-testing Production: | |
| 41 | + * Please **setup a local environment** instead whenever possible. Most of our code is open source (see above). | |
| 42 | + * If that's not possible, **limit any data access/modification** to the bare minimum necessary to reproduce a PoC. | |
| 43 | + * **_Don't_ automate form submissions!** That's very annoying for us, because it adds extra work for the volunteers who manage those systems, and reduces the signal/noise ratio in our communication channels. | |
| 44 | + * To be eligible for a bounty, all of these guidelines must be followed. | |
| 45 | +* Be Patient - Give us a reasonable time to correct the issue before you disclose the vulnerability. | |
| 46 | + | |
| 47 | +We also expect you to comply with all applicable laws. You're responsible to pay any taxes associated with your bounties. | |