Skip to content
This repository has been archived by the owner on Nov 16, 2022. It is now read-only.

Security Radar 8 #570

Closed
gratipay-bot opened this issue Apr 10, 2016 · 1 comment
Closed

Security Radar 8 #570

gratipay-bot opened this issue Apr 10, 2016 · 1 comment

Comments

@gratipay-bot
Copy link

← Security Radar 7


Docs

http://inside.gratipay.com/howto/sweep-the-radar

Scope

This radar covers Gratipay's security program, including:

Queue

Unclear Risk

https://hackerone.com/reports/117195

Severe Risk
Moderate Risk

https://hackerone.com/reports/127218
https://hackerone.com/reports/128844

Mild Risk

https://hackerone.com/reports/76304
https://hackerone.com/reports/80907
https://hackerone.com/reports/90805
https://hackerone.com/reports/108645
https://hackerone.com/reports/109161

https://hackerone.com/reports/111325
https://hackerone.com/reports/117187
https://hackerone.com/reports/117739
https://hackerone.com/reports/117984
https://hackerone.com/reports/118023

https://hackerone.com/reports/118699
https://hackerone.com/reports/123688
https://hackerone.com/reports/123697
https://hackerone.com/reports/128121

Theoretical Risk

https://hackerone.com/reports/78151
https://hackerone.com/reports/90777
https://hackerone.com/reports/116147
https://hackerone.com/reports/117142
https://hackerone.com/reports/117330

https://hackerone.com/reports/117386
https://hackerone.com/reports/117833
https://hackerone.com/reports/120026
https://hackerone.com/reports/123742
https://hackerone.com/reports/123942

https://hackerone.com/reports/123897
https://hackerone.com/reports/124096
https://hackerone.com/reports/127824
https://hackerone.com/reports/127949
https://hackerone.com/reports/127995

gratipay/gratipay.com#823

@chadwhitacre
Copy link
Contributor

chadwhitacre commented Apr 14, 2016

Once we deploy #573 we can refer researchers to the "No Risk" listing for known issues that are wont-fix. That may prevent some low-quality reports. I'd also like to:

  • retitle all issues so that they display more consistently (lower-case, verb first)
  • disclose all tickets closed as "Informative" to populate the "No Risk" listing

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants