Skip to content

Commit 0c182d9

Browse files
committed
doc: add h1 summary to security release process
PR-URL: nodejs/node#49112 Reviewed-By: Moshe Atlow <[email protected]> Reviewed-By: Matteo Collina <[email protected]> Reviewed-By: Michael Dawson <[email protected]>
1 parent 43d661b commit 0c182d9

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

graal-nodejs/doc/contributing/security-release-process.md

+5
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,8 @@ The current security stewards are documented in the main Node.js
5656
* [ ] pre-release: _**LINK TO PR**_
5757
* [ ] post-release: _**LINK TO PR**_
5858
* List vulnerabilities in order of descending severity
59+
* Use the "summary" feature in HackerOne to sync post-release content
60+
and CVE requests. Example [2038134](https://hackerone.com/bugs?subject=nodejs\&report_id=2038134)
5961
* Ask the HackerOne reporter if they would like to be credited on the
6062
security release blog page:
6163
```text
@@ -81,6 +83,9 @@ The current security stewards are documented in the main Node.js
8183
between Security Releases.
8284
* Pass `make test`
8385
* Have CVEs
86+
* Use the "summary" feature in HackerOne to create a description for the
87+
CVE and the post release announcement.
88+
Example [2038134](https://hackerone.com/bugs?subject=nodejs\&report_id=2038134)
8489
* Make sure that dependent libraries have CVEs for their issues. We should
8590
only create CVEs for vulnerabilities in Node.js itself. This is to avoid
8691
having duplicate CVEs for the same vulnerability.

0 commit comments

Comments
 (0)