File tree Expand file tree Collapse file tree 1 file changed +6
-5
lines changed
apps/site/pages/en/blog/announcements Expand file tree Collapse file tree 1 file changed +6
-5
lines changed Original file line number Diff line number Diff line change @@ -11,18 +11,19 @@ higher** to submit vulnerability reports to the Node.js project.
1111
1212## Why This Change
1313
14- The Node.js security team has experienced a significant increase in low-quality, AI-generated vulnerability
15- reports. Triaging these reports consumes time and energy that could be spent on legitimate security work.
16- We consider this volume of noise a denial-of-service against the project's security process.
14+ The Node.js security team has experienced a significant increase in low-quality reports.
15+ This trend has been increasing over the years, and over the holidays it crossed the threshold
16+ that we can actually handle. Between December 15th and January 15th, we received over 30 reports.
17+ Triaging these reports consumes time and energy that could be spent on legitimate security work.
1718
1819By requiring a minimum Signal score, we ensure that reporters have a proven track record of submitting
1920valid security reports, while still allowing newer researchers to participate with a limited number of
2021submissions.
2122
2223## What This Means for You
2324
24- - ** Researchers with [ signal] [ Signal ] >= 1.0** : You can continue reporting vulnerabilities through HackerOne as usual
25- - ** New researchers or those below the threshold** : You can still reach the security team through the
25+ - ** New researchers or researchers with [ signal] [ Signal ] >= 1.0** : You can continue reporting vulnerabilities through HackerOne as usual
26+ - ** Those below the threshold** : You can still reach the security team through the
2627 [ OpenJS Foundation Slack] ( https://slack-invite.openjsf.org/ ) . Contact us there to discuss potential
2728 vulnerabilities
2829
You can’t perform that action at this time.
0 commit comments