A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an origanisation will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifable via a simple way, a security.txt notice.
# Our security address Contact: <a href='mailto:security@samba.org'>security@samba.org</a> # Our OpenPGP key Encryption: <a href='https://download.samba.org/pub/samba/samba-pubkey.asc'>https://download.samba.org/pub/samba/samba-pubkey.asc</a>
This policy crawled by Onyphe on the 2021-01-04 is sorted as securitytxt.
FireBounty © 2015-2021