Skip to content

Commit

Permalink
BUG-BOUNTY.md: clarify the third party situation
Browse files Browse the repository at this point in the history
We do not pay bounties for problems in other libraries.

Closes #13560
  • Loading branch information
bagder committed May 14, 2024
1 parent 22d8ce1 commit 87b6fe1
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions docs/BUG-BOUNTY.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,13 @@ infrastructure.
The curl security team is the sole arbiter if a reported flaw is subject to a
bounty or not.

## Third parties

The curl bug bounty does not cover flaws in third party dependencies
(libraries) used by curl or libcurl. If the bug triggers because of curl
behaving wrongly or abusing a third party dependency, the problem is rather in
curl and not in the dependency and then the bounty might cover the problem.

## How are vulnerabilities graded?

The grading of each reported vulnerability that makes a reward claim is
Expand Down

0 comments on commit 87b6fe1

Please sign in to comment.