Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migrate Pocket's bug bounty program to Mozilla #22

Open
bhourigan opened this issue Oct 8, 2018 · 5 comments
Open

Migrate Pocket's bug bounty program to Mozilla #22

bhourigan opened this issue Oct 8, 2018 · 5 comments

Comments

@bhourigan
Copy link

Pocket independently operates their own bounty program through HackerOne. Let's get this under Mozilla's program and classify Pocket's web properties.

It's been requested that Pocket's HoF list be maintained somehow throughout this migration.

@april
Copy link
Contributor

april commented Oct 8, 2018

I can do this! Is my understanding that you want getpocket.com to be listed under the Core section of eligible bug bounty websites?

@bhourigan
Copy link
Author

That's correct. I'd also like to maintain the Pocket HoF list to whatever extent is possible.

https://help.getpocket.com/article/870-pocket-security-overview

@april
Copy link
Contributor

april commented Oct 8, 2018

Do you want to merge it into the Mozilla Web Hall of Fame? Or leave it as is? For easy of maintenance, I'd prefer to not to maintain a separate Pocket list going forward.

@bhourigan
Copy link
Author

If it's easier for you we can maintain our own HoF for historical purposes. New submissions would be on Mozilla's page.

@april
Copy link
Contributor

april commented Oct 8, 2018

It's up to you! The actual client and web bug bounty lists are maintained in this repository:

https://github.com/mozilla/foundation-security-advisories/tree/master/bug-bounty-hof

So if you're up for migrating it, I'd be happy to approve the PR. Otherwise just leaving the historical one as-is sounds like a solid plan.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants