Page Menu
Home
Phabricator
Search
Configure Global Search
Log In
Files
F15435065
D8538.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Award Token
Flag For Later
Size
1 KB
Referenced Files
None
Subscribers
None
D8538.diff
View Options
diff --git a/src/docs/user/reporting_security.diviner b/src/docs/user/reporting_security.diviner
new file mode 100644
--- /dev/null
+++ b/src/docs/user/reporting_security.diviner
@@ -0,0 +1,41 @@
+@title Reporting Security Vulnerabilities
+@group intro
+
+Describes how to report security vulnerabilities in Phabricator.
+
+= Overview =
+
+Phabricator runs a disclosure and award program through
+[[ https://www.hackerone.com/ | HackerOne ]]. This program is the best way to
+submit security issues to us, and awards responsible disclosure of
+vulnerabilities with cash bounties. You can find our project page
+here:
+
+(NOTE) https://hackerone.com/phabricator
+
+The project page has detailed information about the scope of the program and
+how to participate.
+
+We have a 24 hour response timeline, and are usually able to respond to (and,
+very often, fix) issues more quickly than that.
+
+= Other Channels =
+
+You can also contact us on another channel if you prefer. See
+@{article:Give Feedback! Get Support!} for a list of ways to get in touch
+with us.
+
+= Getting Notified =
+
+When we fix significant security vulnerabilities, we currently publish
+information:
+
+ - on our [[ https://www.facebook.com/phabricator | Facebook Page ]];
+ - on our [[ https://twitter.com/phabricator | Twitter Feed ]];
+ - and on IRC (`#phabricator` on FreeNode).
+
+If you'd prefer to receive information on other channels, let us know.
+
+General information about security is reported monthly in the
+[[ http://phabricator.org/changelog/ | Changelog ]]. This includes low impact
+issues, reports we did not act on, and other details.
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Mar 26 2025, 6:41 AM (6 w, 20 h ago)
Storage Engine
blob
Storage Format
Encrypted (AES-256-CBC)
Storage Handle
7706935
Default Alt Text
D8538.diff (1 KB)
Attached To
Mode
D8538: Document the security vulnerability reporting policy
Attached
Detach File
Event Timeline
Log In to Comment