curl / Mailing Lists / curl-library / Single Mail


Re: bug bounty reward amounts

From: Daniel Stenberg via curl-library <>
Date: Sat, 29 Sep 2018 15:18:06 +0200 (CEST)

On Fri, 28 Sep 2018, Daniel Stenberg via curl-library wrote:

> I think it might help us to attract more security researchers if we spell
> out exactly how much money we intend to pay as rewards for potential finds -
> especially now when have gotten pledges for a notable sum to use for this.
> Here's a proposal from me.

I created a pull-request[1] with this proposal converted to documentation.
I'll appreciate your input!

You can view that markdown file[2] straight from the PR if you want.

[1] =
[2] =

Received on 2018-09-29