Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Participating in Security Bug Bounty program #49

Closed
Zsailer opened this issue Feb 3, 2023 · 2 comments
Closed

Participating in Security Bug Bounty program #49

Zsailer opened this issue Feb 3, 2023 · 2 comments

Comments

@Zsailer
Copy link
Member

Zsailer commented Feb 3, 2023

At yesterday's meeting, we discussed Jupyter Server's participation in the a Security Bug Bounty program offered to Jupyter subprojects sponsored by the European Commission. Read more about it from @jasongrout's thread on the JupyterLab Team Compass page.

We elected to participate in this program, starting as soon as possible. I'll be sending the email today to enlist ourselves.

I (@Zsailer), @3coins, @jess-x, @andrii-i, and (when available) @kevin-bates agreed to help triage any issues that are created by this program.

The following repos will be added to the program:

  • jupyter_server
  • jupyverse
  • enterprise_gateway
  • jupyter_client (in collaboration with the Jupyter Standards team)
@3coins
Copy link

3coins commented Feb 3, 2023

@Zsailer I noticed that you have mentioned security group email as the route for reporting security reports. Using the group email for reporting bugs from all projects might be chaotic.
Should we rather use the Github's CVE process to document these bugs? There are 2 advantages:

  1. We will have a dedicated place to track bugs by project, for cross project bugs, we can ask to report on the jupyter/security project.
  2. Reporters are less likely to report spurious data as the Github's CVE form has some expected inputs so provides some structure for the reporter to add data.

@Zsailer
Copy link
Member Author

Zsailer commented Nov 8, 2023

Closing, since the bug bounty program is finished. Thanks all!

@Zsailer Zsailer closed this as completed Nov 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants