@@ -92,8 +92,6 @@ When reporting security vulnerabilities, reporters must adhere to the following
9292Failure to follow these guidelines may result in:
9393
9494* Rejection of the vulnerability report.
95- * Forfeiture of any potential bug bounty.
96- * Temporary or permanent ban from the bug bounty program.
9795* Legal action in cases of malicious intent.
9896
9997## The Node.js threat model
@@ -103,7 +101,7 @@ underlying operating system. Vulnerabilities that require the compromise
103101of these trusted elements are outside the scope of the Node.js threat
104102model.
105103
106- For a vulnerability to be eligible for a bug bounty , it must be a
104+ For a report to be considered a valid vulnerability , it must be a
107105vulnerability in the context of the Node.js threat model. In other
108106words, it cannot assume that a trusted element (such as the operating
109107system) has been compromised.
@@ -118,7 +116,6 @@ documentation:
118116* Security vulnerabilities that only affect experimental platforms will ** not** be accepted as valid security issues.
119117* Any issues on experimental platforms will be treated as normal bugs.
120118* No CVEs will be issued for issues that only affect experimental platforms
121- * Bug bounty rewards are not available for experimental platform-specific issues
122119
123120This policy recognizes that experimental platforms may not compile, may not
124121pass the test suite, and do not have the same level of testing and support
@@ -163,7 +160,6 @@ acceptable as valid security issues.
163160 security issues.
164161* Any issues with these features will be treated as normal bugs.
165162* No CVEs will be issued for issues that only affect compile-time flag or V8 flag features.
166- * Bug bounty rewards are not available for compile-time flag or V8 flag feature issues.
167163
168164This policy recognizes that experimental features behind compile-time flags
169165are not ready for public consumption and may have incomplete implementations,
0 commit comments