mirror of
https://github.com/curl/curl.git
synced 2024-12-27 06:59:43 +08:00
BUG-BOUNTY.md: clarify that the curl security team decides
Closes #12975
This commit is contained in:
parent
8e83b6b429
commit
8dbc3c7a6b
@ -48,6 +48,9 @@ their bounty from the [Internet Bug Bounty](https://hackerone.com/ibb).
|
||||
Bounties need to be requested within twelve months from the publication of the
|
||||
vulnerability.
|
||||
|
||||
The curl security team reserves themselves the right to deny or allow bug
|
||||
bounty payouts on its own discretion. There is no appeals process.
|
||||
|
||||
## Product vulnerabilities only
|
||||
|
||||
This bug bounty only concerns the curl and libcurl products and thus their
|
||||
|
Loading…
Reference in New Issue
Block a user