doc: add security escalation policy · nodejs/node@bd767c5

Original file line numberDiff line numberDiff line change

@@ -15,6 +15,13 @@ you informed of the progress being made towards a fix and full announcement,

1515

and may ask for additional information or guidance surrounding the reported

1616

issue.

1717
18+

If you do not receive an acknowledgement of your report within 6 business

19+

days, or if you cannot find a private security contact for the project, you

20+

may escalate to the OpenJS Foundation CNA at `security@lists.openjsf.org`.

21+
22+

If the project acknowledges your report but does not provide any further

23+

response or engagement within 14 days, escalation is also appropriate.

24+
1825

### Node.js bug bounty program

1926
2027

The Node.js project engages in an official bug bounty program for security