Skip to content

Experimental Features - Security expectations  #1299

@RafaelGSS

Description

@RafaelGSS

Hello all!

We have had private discussions about handling valid vulnerabilities on experimental features. The TSC would be the best group to decide which point of view we look at for those vulnerability reports.

IMO even being experimental, any feature should be secure when it lands. Therefore, any vulnerability found should be reported and accepted at HackerOne. In this way, we can enforce a collaborative design by awarding security researchers that invest their time when a feature is still experimental and, thus, we guarantee a stable feature when the time comes.

I know @jasnell and others have different opinions, so would be great to hear your thoughts.

Once we have a decision, we probably need to document it properly (likely on nodejs/security-wg#799).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions