mirror of
https://github.com/curl/curl.git
synced 2024-11-27 05:50:21 +08:00
BUG-BOUNTY.md: clarify the third party situation
We do not pay bounties for problems in other libraries. Closes #13560
This commit is contained in:
parent
22d8ce1970
commit
87b6fe1695
@ -67,6 +67,13 @@ infrastructure.
|
||||
The curl security team is the sole arbiter if a reported flaw is subject to a
|
||||
bounty or not.
|
||||
|
||||
## Third parties
|
||||
|
||||
The curl bug bounty does not cover flaws in third party dependencies
|
||||
(libraries) used by curl or libcurl. If the bug triggers because of curl
|
||||
behaving wrongly or abusing a third party dependency, the problem is rather in
|
||||
curl and not in the dependency and then the bounty might cover the problem.
|
||||
|
||||
## How are vulnerabilities graded?
|
||||
|
||||
The grading of each reported vulnerability that makes a reward claim is
|
||||
|
Loading…
Reference in New Issue
Block a user