Files
freeCodeCamp/docs/security.md
Mrugesh Mohapatra 6f0d2fa502 docs: update the security policy (#45776)
* docs: update the security policy

* chore: apply suggestions from code review

Co-authored-by: Naomi Carrigan <nhcarrigan@gmail.com>

Co-authored-by: Naomi Carrigan <nhcarrigan@gmail.com>
2022-04-25 20:16:20 +05:30

3.1 KiB

freeCodeCamp.org's Security Policy

This document outlines our security policy for the codebases, platforms that we operate, and how to report vulnerabilities.

Reporting a Vulnerability

Note

If you think you have found a vulnerability, please report responsibly. Do not create GitHub issues for security issues. Instead follow this guide.

Guidelines

We appreciate a responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:

  1. Ensure that you are using the latest, stable and updated versions of the Operating System and Web Browser(s) available to you on your machine.
  2. We consider using tools & online utilities to report issues with SPF & DKIM configs, or SSL Server tests, etc. in the category of "beg bounties" and are unable to respond to these reports.
  3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our Hall of Fame list, provided the reports are not low-effort.

Reporting

After confirming the above guidelines, please feel free to either send an email to possible-security-issue [at] freecodecamp.org. You can also send us an PGP encrypted message at flowcrypt.com/me/freecodecamp if you prefer.

Once you report a vulnerability, we will look into it and make sure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.

Platforms & Codebases

Here is a list of the platforms and codebases we are accepting reports for:

Learn Platform

Version Branch Supported Website active
production prod-current Yes freecodecamp.org/learn
staging prod-staging Yes freecodecamp.dev/learn
development main No

Publication Platform

Version Supported Website active
production Yes freecodecamp.org/news
localized Yes freecodecamp.org/<language>/news

Mobile App

Version Supported Website active
production Yes https://play.google.com/store/apps/details?id=org.freecodecamp

Other Platforms

Apart from the above, we are also accepting reports for repositories hosted on GitHub, under the freeCodeCamp organization.

Other Self-hosted Applications

We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability please ensure that it is not a bug in the upstream software.