Thanks to visit codestin.com
Credit goes to github.com

Skip to content

docs: recommend bug bounty program#6

Merged
Proximyst merged 1 commit intomainfrom
mariell/recommend-bug-bounty
Dec 18, 2025
Merged

docs: recommend bug bounty program#6
Proximyst merged 1 commit intomainfrom
mariell/recommend-bug-bounty

Conversation

@Proximyst
Copy link
Member

This recommends the bug bounty program.

I've intentionally avoided using words that explicitly say we prefer one over the other, instead relying on people's natural gravitation towards the first presented option, along with spreading the link to the bug bounty program several times over the document to put our foot on the scale a little bit.

The point is to try to get people to use bug bounties, but we still do not want to discredit the email reporting avenue as it is and will remain equally valid, should someone not have access to intigriti, or wish not to use it for any reason.

Copy link
Member

@simonc6372 simonc6372 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like the wording. We should probably also update https://grafana.com/legal/report-a-security-issue/ with similar wording.

Do any projects/repos have their own security.md we should consider updating ?

@Proximyst
Copy link
Member Author

Proximyst commented Dec 18, 2025

@simonc6372 Good call!

  • k6: has the same content as prior to this PR. ✅
  • grafana: has the same content as after this PR. ✅
  • tempo: has the same content as prior to this PR. ✅
  • mimir: has the same content as after to this PR. ✅
  • alloy: has the same content as prior to this PR. ✅
  • faro-web-sdk: has the same content as prior to this PR. ✅
  • grafana-plugin-sdk-go: has the same content as prior to this PR. ✅
  • alloy-remote-config: has the same content as prior to this PR. ✅
  • nanogit: has the same content as prior to this PR. ✅
  • synthetic-monitoring-agent: links to grafana/grafana's SECURITY.md ✅
  • cloudcost-exporter: same as prior, but with old key. ✅
  • pyroscope-rs: asks to send emails to [email protected] rather than what every other project does. ✅

@Proximyst Proximyst merged commit 79d90ff into main Dec 18, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants