Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit c62dd6e

Browse files
committed
report components article
1 parent 72059fd commit c62dd6e

7 files changed

+71
-0
lines changed
Loading
Loading
Loading
5.18 KB
Loading
281 KB
Loading

docs/programs/report-components.md

Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
---
2+
title: "Report Components"
3+
path: "/programs/report-components.html"
4+
id: "programs/report-components"
5+
---
6+
7+
Reports in your inbox consist of different components to give you a holistic view of the vulnerability.
8+
9+
### Hacker Info
10+
The top of the report shows the hacker that submitted the report as well as their hacking statistics by reputation, signal, and impact.
11+
12+
![hacker info](./images/report-timeline-hacker-info.png)
13+
14+
### Report ID and Title
15+
Below the hacker information is the report ID number and title. You can change the report title to your internal naming conventions. The color behind the report number represents the state the report is in. These are the different colors and the [report states](report-states.html) they represent:
16+
17+
Color | Report State
18+
----- | ---------
19+
Purple | New
20+
Light Blue | Needs more info
21+
Yellow | [Retesting](retesting.html)
22+
Green | Resolved
23+
Orange | Triaged
24+
Brown | Duplicate
25+
Grey | Informative
26+
Red | Not Applicable
27+
28+
![Report ID and Title](./images/report-timeline-report-id-title.png)
29+
30+
### Report Metadata
31+
You’ll be able to view these metadata fields underneath the title of your report:
32+
33+
Metadata Field | Details
34+
-------------- | --------
35+
State | The state the report is in.
36+
Disclosed | The date the report was disclosed. Only shows for reports that were disclosed.
37+
Reported To | The name of the program the report was submitted to.
38+
Asset | The specific asset the vulnerability was found on.
39+
Reference | Add a reference to the CVE ID and to the ticket associated with the report in your issue tracking tool.
40+
Assigned to | *(An internal field that is only seen by the program’s security team)* The person on your security team that's assigned to triage or manage the report.
41+
Weakness | The type of weakness of the vulnerability.
42+
Bounty | (*Only shows for resolved reports that were given a bounty*) How much bounty the report was awarded.
43+
Severity | The severity level of the vulnerability.
44+
Participants | All of the hackers involved in finding the vulnerability.
45+
Notifications | Indicates whether you have notifications enabled or disabled for actions on your program.
46+
Visibility | Indicates the status of disclosure of the vulnerability. You can also choose to redact private information from the report.
47+
48+
![report metadata](./images/report-timeline-metadata.png)
49+
50+
### Summary
51+
Either your security team or the hacker(s) involved with the report can choose to provide an optional summary of the report. Including a summary helps future viewers of the report to understand the context without having to scroll through the entire report. Click **ADD SUMMARY** to add a summary to the report.
52+
53+
![report summary section](./images/report-timeline-summary.png)
54+
55+
### Timeline
56+
The report timeline shows all of the activity that occurs in the report between you and the hackers involved. It will show when:
57+
* You or the hacker adds a comment
58+
* The state of the report changes
59+
* The report has been assigned or unassigned
60+
* A bounty is set
61+
* A bounty has been given
62+
* A hacker requests mediation
63+
* You or the hacker requests public disclosure
64+
65+
Internal comments and actions made within your program security team will be surrounded with a red box and a lock icon to denote that the comment will only be seen by internal members and not by hackers.
66+
67+
If you have [hackbot](hackbot.html) enabled, you’ll also be able to view your suggestions from hackbot, which will also be internal.
68+
69+
![report timeline](./images/report_timeline.png)

src/pages/programs/programs-nav.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -121,6 +121,8 @@
121121
path: /programs/report-actions.html
122122
- title: Report States
123123
path: /programs/report-states.html
124+
- title: Report Components
125+
path: /programs/report-components.html
124126
- title: Quality Reports
125127
path: /programs/quality-reports.html
126128
- title: Locking Reports

0 commit comments

Comments
 (0)