Skip to content

Commit 932f44b

Browse files
committed
fixup! Blog: add HackerOne signal 1 post
1 parent d241fee commit 932f44b

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

apps/site/pages/en/blog/announcements/hackerone-signal-requirement.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,18 +11,19 @@ higher** to submit vulnerability reports to the Node.js project.
1111

1212
## Why This Change
1313

14-
The Node.js security team has experienced a significant increase in low-quality, AI-generated vulnerability
15-
reports. Triaging these reports consumes time and energy that could be spent on legitimate security work.
16-
We consider this volume of noise a denial-of-service against the project's security process.
14+
The Node.js security team has experienced a significant increase in low-quality reports.
15+
This trend has been increasing over the years, and over the holidays it crossed the threshold
16+
that we can actually handle. Between December 15th and January 15th, we received over 30 reports.
17+
Triaging these reports consumes time and energy that could be spent on legitimate security work.
1718

1819
By requiring a minimum Signal score, we ensure that reporters have a proven track record of submitting
1920
valid security reports, while still allowing newer researchers to participate with a limited number of
2021
submissions.
2122

2223
## What This Means for You
2324

24-
- **Researchers with [signal][Signal] >= 1.0**: You can continue reporting vulnerabilities through HackerOne as usual
25-
- **New researchers or those below the threshold**: You can still reach the security team through the
25+
- **New researchers or researchers with [signal][Signal] >= 1.0**: You can continue reporting vulnerabilities through HackerOne as usual
26+
- **Those below the threshold**: You can still reach the security team through the
2627
[OpenJS Foundation Slack](https://slack-invite.openjsf.org/). Contact us there to discuss potential
2728
vulnerabilities
2829

0 commit comments

Comments
 (0)