Private reporting of a potential security vulnerability
Sim4n6 opened this issue · 6 comments
Sim4n6 commented
Sim4n6 commented
flavorjones commented
Hi! Thanks for asking about our security policy. It's documented in the README:
Because this project is under the Rails umbrella, you should report security concerns following this policy: https://rubyonrails.org/security
We use Hackerone, here's the deeplink: https://hackerone.com/rails
Sim4n6 commented
Thank you for your response.
Sim4n6 commented
Sorry about that, but I'm a bit lost.
Do you suggest please that I initially submit the report via https://hackerone.com/rails?type=team or do I proceed via https://hackerone.com/ibb?type=team , please ?
Regards,
@Sim4n6
Sim4n6 commented
I'm going with https://hackerone.com/rails?view_policy=true right away 👍🏾
flavorjones commented
Thank you.

