Sfoglia il codice sorgente

Clarification that bug bounty not for previously disclosed publicly available CVEs

Signed-off-by: Matt Ray <github@mattray.dev>
Matt Ray 3 anni fa
parent
commit
d2b1076d31
1 ha cambiato i file con 1 aggiunte e 1 eliminazioni
  1. 1 1
      SECURITY.md

+ 1 - 1
SECURITY.md

@@ -22,7 +22,7 @@ The OpenCost project has enabled [Private vulnerability reporting](https://docs.
 
 ### Kubecost Bug Bounty
 
-Kubecost offers a Bug Bounty program that pays $250 USD for unique accepted security bug reports submitted to vulnerability-report@kubecost.com.
+Kubecost offers a Bug Bounty program that pays $250 USD for unique, not previously disclosed publicly available CVEs, and accepted security bug reports submitted to vulnerability-report@kubecost.com.
 
 ## Disclosure policy