Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spend from Node.js Bug Bounty/Security Fund (LFX crowdfunding account) to have collaborator fix urgent vulnerability #1506

Closed
tniessen opened this issue Feb 18, 2024 · 9 comments

Comments

@tniessen
Copy link
Member

Due to a rather unique situation, we are seeking approval for using up to $2000 of the security fund for contracting a collaborator to fix a security vulnerability. Details are available through the private TSC mailing list. Please let us know if there are any concerns or objections by the end of 2024-02-21, and please +1 the issue if you don't have any concerns.

cc @nodejs/tsc

@mcollina
Copy link
Member

+1

@joyeecheung
Copy link
Member

joyeecheung commented Feb 18, 2024 via email

@aduh95
Copy link
Contributor

aduh95 commented Feb 18, 2024

+1

1 similar comment
@gireeshpunathil
Copy link
Member

+1

@MoLow
Copy link
Member

MoLow commented Feb 18, 2024 via email

@anonrig
Copy link
Member

anonrig commented Feb 18, 2024

+1

@mhdawson
Copy link
Member

+1

@tniessen
Copy link
Member Author

Consensus has been reached.

@mhdawson
Copy link
Member

Based on the pre-approval here, and the fix which was published in the recent security release, I'm approving payment for this on behalf of the TSC as per the process in https://github.com/nodejs/TSC/blob/main/Nodejs-Bug-Bounty-Security-Fund.md#disbursements.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

8 participants