Skip to content

Conversation

@ThatGuyLLC
Copy link

The Security Council has approved a new SECURITY.md aligned with the bug-bounty process. Please update your project’s SECURITY.md with the correct links for your project and confirm that private vulnerability reporting is enabled for your repository. All bug bounty details found here:
https://opensourcecommittee.docs.intersectmbo.org/about/paid-open-source-model-posm/bug-bounty-program'

opensourcecommittee.docs.intersectmbo.org

Description

reasonably detailed description of the pull request

Checklist

Quality

  • Commit sequence makes sense and have useful messages, see ref.
  • New tests are added and existing tests are updated.
  • Self-reviewed the PR.

Maintenance

  • Linked an issue or added the PR to the current sprint of ouroboros-network project.
  • Added labels.
  • Updated changelog files.
  • The documentation has been properly updated, see ref.

The Security Council has approved a new SECURITY.md aligned with the bug-bounty process. Please update your project’s SECURITY.md with the correct links for your project and confirm that private vulnerability reporting is enabled for your repository.
All bug bounty details found here:
https://opensourcecommittee.docs.intersectmbo.org/about/paid-open-source-model-posm/bug-bounty-program'

opensourcecommittee.docs.intersectmbo.org
Please report (suspected) security vulnerabilities to [email protected]. You will receive a
response from us within 48 hours. If the issue is confirmed, we will release a patch as soon
as possible.
The Cardano open source project (xxx) is committed to ensuring the security of
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you mean:

Suggested change
The Cardano open source project (xxx) is committed to ensuring the security of
The Cardano open source project `ouroboros-network` is committed to ensuring the security of

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes

* any workarounds or mitigations
### Reporting a Vulnerability

If you discover a security vulnerability in xxxx, we encourage you to
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
If you discover a security vulnerability in xxxx, we encourage you to
If you discover a security vulnerability in `ouroboros-network`, we encourage you to

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes

If you discover a security vulnerability in xxxx, we encourage you to
responsibly disclose it to us. To report a vulnerability, please use
the [private reporting form on
GitHub](https://github.com/input-output-hk/mithril/security/advisories/new)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We certainly shouldn't use input-output-hk/mithril. What I suggest below is also wrong since it's 404:

Suggested change
GitHub](https://github.com/input-output-hk/mithril/security/advisories/new)
GitHub](https://github.com/IntersectMBO/ouroboros-network/security/advisories/new)

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes its for use to something applicable to yall's project left mithril there as reference

Copy link
Collaborator

@coot coot Oct 23, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The link I posted is 404, and there's no way to create a new advisory in the ouroboros-network repo. You'll need to configure it correctly.


- A description of the vulnerability and its potential impact.
- Steps to reproduce the vulnerability.
- The version of `xxxx` package where the vulnerability exists.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- The version of `xxxx` package where the vulnerability exists.
- The name and version of one of the packages in `ouroboros-network` repository where the vulnerability exists.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes

Comment on lines +92 to +93
To report a security vulnerability, please use [GitHub
form]((add project github form for your project)). Should you experience any issues reporting via GitHub or have other questions, Please contact [Security]([email protected]).
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The link is invalid. What should it be? Should it link to ouroboros-network advisory, cardano-node advisory?

It should be done consistently across all cardano-node repos.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

does it serve best as project specific or meta project specific


This Security Vulnerability Disclosure Policy may be updated or
revised as necessary. Please check the latest version of this policy
on the [xxxx repository]((add link for your project)).
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please fix the link.


## Conclusion

The xxxx project greatly appreciates the assistance of the security
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The xxxx project greatly appreciates the assistance of the security
The `ouroboros-network` project greatly appreciates the assistance of the security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

2 participants