FOSSA bug bounty program

Florian Weimer fw@deneb.enyo.de
Mon Dec 31 13:08:00 GMT 2018


glibc is listed as a participating project here:

  <https://juliareda.eu/2018/12/eu-fossa-bug-bounties/>

Has anyone been in contact with them?  How do they propose to deal
with their findings?

The default terms of the vulnerability sharing platform they chose are
incompatible with how we handle vulnerabilities, with collaboration on
patch development across multiple organizations and coordinated
disclosure for important vulnerabilities.



More information about the Libc-alpha mailing list