Skip to content

How long do you wait between reporting vulnerabilities and publishing the query that found them? #120

Answered by nicowaisman
p- asked this question in General
Discussion options

You must be logged in to vote

Hey @p-,
This are all great question that have no easy or correct answer.
Queries are a fantastic way to find vulnerabilities but requires someone to look at them. That process, triaging, requires someone time to do it. Sometimes is the developer and sometime is a security researcher. Right now we are trying to find creative ways to encourage the community and developers to help us triage some of those bugs (Which is the reason why we built the Bug Slayer bug bounty program. Use the query you write to report vulnerabilities to vendors).
We do believe that a query is knowledge that we want everyone to share them with the community to get better. The way our code-scanning workflow works for…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by RasmusWL
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants