doc: clarify experimental platform vulnerability policy · nodejs/node@40b217a · GitHub
Skip to content

Commit 40b217a

Browse files
mcollinatargos
authored andcommitted
doc: clarify experimental platform vulnerability policy
Adds a new section to the threat model specifying that security vulnerabilities affecting only experimental platforms will not be accepted as valid security issues and will be treated as normal bugs. This clarifies that experimental OS/hardware combinations do not qualify for CVEs or bug bounty rewards, aligning with their limited testing and support infrastructure. Signed-off-by: Matteo Collina <hello@matteocollina.com> PR-URL: #59591 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Michaël Zasso <targos@protonmail.com> Reviewed-By: Jordan Harband <ljharb@gmail.com>
1 parent f5ece45 commit 40b217a

1 file changed

Lines changed: 16 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 16 additions & 0 deletions

0 commit comments

Comments
 (0)