-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Closed
Description
It's now good practice to have a SECURITY.md file that explains a well-defined process for reporting vulnerabilities. Core has this too:
https://github.com/bitcoin/bitcoin/blob/master/SECURITY.md
This is also a good chance to think about the process, i.e., who should actually be informed about vulnerabilities in this library. This is not completely obvious since this library somehow belongs to Bitcoin Core (I mean the software, not the "organization"/group of people) but on the other hand is maintained separately.
Metadata
Metadata
Assignees
Labels
No labels