| 1 |
<!-- |
| 2 |
This policy template was created using the HackerOne Policy Builder [1], |
| 3 |
with guidance from the National Telecommunications and Information |
| 4 |
Administration Coordinated Vulnerability Disclosure Template [2]. |
| 5 |
--> |
| 6 |
|
| 7 |
# Vulnerability Disclosure Policy (VDP) |
| 8 |
|
| 9 |
## Brand Promise |
| 10 |
|
| 11 |
<!-- |
| 12 |
This is your brand promise. Its objective is to "demonstrate a clear, good |
| 13 |
faith commitment to customers and other stakeholders potentially impacted by |
| 14 |
security vulnerabilities" [2]. |
| 15 |
--> |
| 16 |
|
| 17 |
Keeping user information safe and secure is a top priority, and we welcome the |
| 18 |
contribution of external security researchers. |
| 19 |
|
| 20 |
## Scope |
| 21 |
|
| 22 |
<!-- |
| 23 |
This is your initial scope. It tells vulnerability finders and reporters |
| 24 |
"which systems and capabilities are 'fair game' versus 'off limits'" [2]. |
| 25 |
For software packages, this is often a list of currently maintained versions |
| 26 |
of the package. |
| 27 |
--> |
| 28 |
|
| 29 |
If you believe you've found a security issue in software that is maintained in |
| 30 |
this repository, we encourage you to notify us. |
| 31 |
|
| 32 |
| Version | In scope | Source code | |
| 33 |
| ------- | :------: | ----------- | |
| 34 |
| latest | � |
| 35 |
| https://github.com/ramsey/collection | |
| 36 |
|
| 37 |
## How to Submit a Report |
| 38 |
|
| 39 |
<!-- |
| 40 |
This is your communication process. It tells security researchers how to |
| 41 |
contact you to report a vulnerability. It may be a link to a web form that |
| 42 |
uses HTTPS for secure communication, or it may be an email address. |
| 43 |
Optionally, you may choose to include a PGP public key, so that researchers |
| 44 |
may send you encrypted messages. |
| 45 |
--> |
| 46 |
|
| 47 |
To submit a vulnerability report, please contact us at [email protected]. |
| 48 |
Your submission will be reviewed and validated by a member of our team. |
| 49 |
|
| 50 |
## Safe Harbor |
| 51 |
|
| 52 |
<!-- |
| 53 |
This section assures vulnerability finders and reporters that they will |
| 54 |
receive good faith responses to their good faith acts. In other words, |
| 55 |
"we will not take legal action if..." [2]. |
| 56 |
--> |
| 57 |
|
| 58 |
We support safe harbor for security researchers who: |
| 59 |
|
| 60 |
* Make a good faith effort to avoid privacy violations, destruction of data, and |
| 61 |
interruption or degradation of our services. |
| 62 |
* Only interact with accounts you own or with explicit permission of the account |
| 63 |
holder. If you do encounter Personally Identifiable Information (PII) contact |
| 64 |
us immediately, do not proceed with access, and immediately purge any local |
| 65 |
information. |
| 66 |
* Provide us with a reasonable amount of time to resolve vulnerabilities prior |
| 67 |
to any disclosure to the public or a third party. |
| 68 |
|
| 69 |
We will consider activities conducted consistent with this policy to constitute |
| 70 |
"authorized" conduct and will not pursue civil action or initiate a complaint to |
| 71 |
law enforcement. We will help to the extent we can if legal action is initiated |
| 72 |
by a third party against you. |
| 73 |
|
| 74 |
Please submit a report to us before engaging in conduct that may be inconsistent |
| 75 |
with or unaddressed by this policy. |
| 76 |
|
| 77 |
## Preferences |
| 78 |
|
| 79 |
<!-- |
| 80 |
The preferences section sets expectations based on priority and submission |
| 81 |
volume, rather than legal objection or restriction [2]. |
| 82 |
|
| 83 |
According to the NTIA [2]: |
| 84 |
|
| 85 |
This section is a living document that sets expectations for preferences |
| 86 |
and priorities, typically maintained by the support and engineering |
| 87 |
team. This can outline classes of vulnerabilities, reporting style |
| 88 |
(crash dumps, CVSS scoring, proof-of-concept, etc.), tools, etc. Too |
| 89 |
many preferences can set the wrong tone or make reporting findings |
| 90 |
difficult to navigate. This section also sets expectations to the |
| 91 |
researcher community for what types of issues are considered important |
| 92 |
or not. |
| 93 |
--> |
| 94 |
|
| 95 |
* Please provide detailed reports with reproducible steps and a clearly defined |
| 96 |
impact. |
| 97 |
* Include the version number of the vulnerable package in your report |
| 98 |
* Social engineering (e.g. phishing, vishing, smishing) is prohibited. |
| 99 |
|
| 100 |
<!-- |
| 101 |
References |
| 102 |
|
| 103 |
[1] HackerOne. Policy builder. Retrieved from https://hackerone.com/policy-builder/ |
| 104 |
|
| 105 |
[2] NTIA Safety Working Group. 2016. "Early stage" coordinated vulnerability |
| 106 |
disclosure template: Version 1.1. (15 December 2016). Retrieved from |
| 107 |
https://www.ntia.doc.gov/files/ntia/publications/ntia_vuln_disclosure_early_stage_template.pdf |
| 108 |
--> |
| 109 |
|
| 110 |
## Encryption Key for [email protected] |
| 111 |
|
| 112 |
For increased privacy when reporting sensitive issues, you may encrypt your |
| 113 |
message using the following public key: |
| 114 |
|
| 115 |
``` |
| 116 |
-----BEGIN PGP PUBLIC KEY BLOCK----- |
| 117 |
|
| 118 |
mQINBF+Z9gEBEACbT/pIx8RR0K18t8Z2rDnmEV44YdT7HNsMdq+D6SAlx8UUb6AU |
| 119 |
jGIbV9dgBgGNtOLU1pxloaJwL9bWIRbj+X/Qb2WNIP//Vz1Y40ox1dSpfCUrizXx |
| 120 |
kb4p58Xml0PsB8dg3b4RDUgKwGC37ne5xmDnigyJPbiB2XJ6Xc46oPCjh86XROTK |
| 121 |
wEBB2lY67ClBlSlvC2V9KmbTboRQkLdQDhOaUosMb99zRb0EWqDLaFkZVjY5HI7i |
| 122 |
0pTveE6dI12NfHhTwKjZ5pUiAZQGlKA6J1dMjY2unxHZkQj5MlMfrLSyJHZxccdJ |
| 123 |
xD94T6OTcTHt/XmMpI2AObpewZDdChDQmcYDZXGfAhFoJmbvXsmLMGXKgzKoZ/ls |
| 124 |
RmLsQhh7+/r8E+Pn5r+A6Hh4uAc14ApyEP0ckKeIXw1C6pepHM4E8TEXVr/IA6K/ |
| 125 |
z6jlHORixIFX7iNOnfHh+qwOgZw40D6JnBfEzjFi+T2Cy+JzN2uy7I8UnecTMGo3 |
| 126 |
5t6astPy6xcH6kZYzFTV7XERR6LIIVyLAiMFd8kF5MbJ8N5ElRFsFHPW+82N2HDX |
| 127 |
c60iSaTB85k6R6xd8JIKDiaKE4sSuw2wHFCKq33d/GamYezp1wO+bVUQg88efljC |
| 128 |
2JNFyD+vl30josqhw1HcmbE1TP3DlYeIL5jQOlxCMsgai6JtTfHFM/5MYwARAQAB |
| 129 |
tBNzZWN1cml0eUByYW1zZXkuZGV2iQJUBBMBCAA+FiEE4drPD+/ofZ570fAYq0bv |
| 130 |
vXQCywIFAl+Z9gECGwMFCQeGH4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ |
| 131 |
q0bvvXQCywIkEA//Qcwv8MtTCy01LHZd9c7VslwhNdXQDYymcTyjcYw8x7O22m4B |
| 132 |
3hXE6vqAplFhVxxkqXB2ef0tQuzxhPHNJgkCE4Wq4i+V6qGpaSVHQT2W6DN/NIhL |
| 133 |
vS8OdScc6zddmIbIkSrzVVAtjwehFNEIrX3DnbbbK+Iku7vsKT5EclOluIsjlYoX |
| 134 |
goW8IeReyDBqOe2H3hoCGw6EA0D/NYV2bJnfy53rXVIyarsXXeOLp7eNEH6Td7aW |
| 135 |
PVSrMZJe1t+knrEGnEdrXWzlg4lCJJCtemGv+pKBUomnyISXSdqyoRCCzvQjqyig |
| 136 |
2kRebUX8BXPW33p4OXPj9sIboUOjZwormWwqqbFMO+J4TiVCUoEoheI7emPFRcNN |
| 137 |
QtPJrjbY1++OznBc0GRpfeUkGoU1cbRl1bnepnFIZMTDLkrVW6I1Y4q8ZVwX3BkE |
| 138 |
N81ctFrRpHBlU36EdHvjPQmGtuiL77Qq3fWmMv7yTvK1wHJAXfEb0ZJWHZCbck3w |
| 139 |
l0CVq0Z+UUAOM8Rp1N0N8m92xtapav0qCFU9qzf2J5qX6GRmWv+d29wPgFHzDWBm |
| 140 |
nnrYYIA4wJLx00U6SMcVBSnNe91B+RfGY5XQhbWPjQQecOGCSDsxaFAq2MeOVJyZ |
| 141 |
bIjLYfG9GxoLKr5R7oLRJvZI4nKKBc1Kci/crZbdiSdQhSQGlDz88F1OHeCIdQQQ |
| 142 |
EQgAHRYhBOhdAxHd+lus86YQ57Atl5icjAcbBQJfmfdIAAoJELAtl5icjAcbFVcA |
| 143 |
/1LqB3ZjsnXDAvvAXZVjSPqofSlpMLeRQP6IM/A9Odq0AQCZrtZc1knOMGEcjppK |
| 144 |
Rk+sy/R0Mshy8TDuaZIRgh2Ux7kCDQRfmfYBARAAmchKzzVz7IaEq7PnZDb3szQs |
| 145 |
T/+E9F3m39yOpV4fEB1YzObonFakXNT7Gw2tZEx0eitUMqQ/13jjfu3UdzlKl2bR |
| 146 |
qA8LrSQRhB+PTC9A1XvwxCUYhhjGiLzJ9CZL6hBQB43qHOmE9XJPme90geLsF+gK |
| 147 |
u39Waj1SNWzwGg+Gy1Gl5f2AJoDTxznreCuFGj+Vfaczt/hlfgqpOdb9jsmdoE7t |
| 148 |
3DSWppA9dRHWwQSgE6J28rR4QySBcqyXS6IMykqaJn7Z26yNIaITLnHCZOSY8zhP |
| 149 |
ha7GFsN549EOCgECbrnPt9dmI2+hQE0RO0e7SOBNsIf5sz/i7urhwuj0CbOqhjc2 |
| 150 |
X1AEVNFCVcb6HPi/AWefdFCRu0gaWQxn5g+9nkq5slEgvzCCiKYzaBIcr8qR6Hb4 |
| 151 |
FaOPVPxO8vndRouq57Ws8XpAwbPttioFuCqF4u9K+tK/8e2/R8QgRYJsE3Cz/Fu8 |
| 152 |
+pZFpMnqbDEbK3DL3ss+1ed1sky+mDV8qXXeI33XW5hMFnk1JWshUjHNlQmE6ftC |
| 153 |
U0xSTMVUtwJhzH2zDp8lEdu7qi3EsNULOl68ozDr6soWAvCbHPeTdTOnFySGCleG |
| 154 |
/3TonsoZJs/sSPPJnxFQ1DtgQL6EbhIwa0ZwU4eKYVHZ9tjxuMX3teFzRvOrJjgs |
| 155 |
+ywGlsIURtEckT5Y6nMAEQEAAYkCPAQYAQgAJhYhBOHazw/v6H2ee9HwGKtG7710 |
| 156 |
AssCBQJfmfYBAhsMBQkHhh+AAAoJEKtG7710AssC8NcP/iDAcy1aZFvkA0EbZ85p |
| 157 |
i7/+ywtE/1wF4U4/9OuLcoskqGGnl1pJNPooMOSBCfreoTB8HimT0Fln0CoaOm4Q |
| 158 |
pScNq39JXmf4VxauqUJVARByP6zUfgYarqoaZNeuFF0S4AZJ2HhGzaQPjDz1uKVM |
| 159 |
PE6tQSgQkFzdZ9AtRA4vElTH6yRAgmepUsOihk0b0gUtVnwtRYZ8e0Qt3ie97a73 |
| 160 |
DxLgAgedFRUbLRYiT0vNaYbainBsLWKpN/T8odwIg/smP0Khjp/ckV60cZTdBiPR |
| 161 |
szBTPJESMUTu0VPntc4gWwGsmhZJg/Tt/qP08XYo3VxNYBegyuWwNR66zDWvwvGH |
| 162 |
muMv5UchuDxp6Rt3JkIO4voMT1JSjWy9p8krkPEE4V6PxAagLjdZSkt92wVLiK5x |
| 163 |
y5gNrtPhU45YdRAKHr36OvJBJQ42CDaZ6nzrzghcIp9CZ7ANHrI+QLRM/csz+AGA |
| 164 |
szSp6S4mc1lnxxfbOhPPpebZPn0nIAXoZnnoVKdrxBVedPQHT59ZFvKTQ9Fs7gd3 |
| 165 |
sYNuc7tJGFGC2CxBH4ANDpOQkc5q9JJ1HSGrXU3juxIiRgfA26Q22S9c71dXjElw |
| 166 |
Ri584QH+bL6kkYmm8xpKF6TVwhwu5xx/jBPrbWqFrtbvLNrnfPoapTihBfdIhkT6 |
| 167 |
nmgawbBHA02D5xEqB5SU3WJu |
| 168 |
=eJNx |
| 169 |
-----END PGP PUBLIC KEY BLOCK----- |
| 170 |
``` |
| 171 |
|