Skip to content

Commit 09e61e1

Browse files
authored
Provide a link to bug bounty program in security policy (#5004)
Following discussion with folks at the CF.
2 parents 95b1dc7 + 98d5ff5 commit 09e61e1

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

SECURITY.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,20 @@ Please include as much details as needed to clearly qualify the issue:
2626
* The version of `cardano-wallet` package where the vulnerability exists.
2727
* Any relevant proof-of-concept or exploit code (if applicable).
2828

29+
#### Bug Bounty program
30+
31+
The [Cardano Foundation](https://www.cardanofoundation.org) sponsors a
32+
bug bounty program for cardano-wallet. You can be entitled to a reward
33+
for responsible disclosure of a vulnerability by reporting your
34+
findings on the [program's
35+
page](https://immunefi.com/bug-bounty/cardanofoundation/scope/#top).
36+
37+
Please note the former is only valid for the purpose of participating
38+
in the bug bounty program, and technical details about the
39+
vulnerability shall be analysed using GitHub interface. Make sure you
40+
put a link to the draft security advisory into your bug bounty program
41+
submission.
42+
2943
### Processing Vulnerability
3044

3145
1. **Acknowledgment**: The team acknowledges the receipt of your

0 commit comments

Comments
 (0)