Skip to content

Security: taskcluster/taskcluster

SECURITY.md

Security Policy

Overview

This code and its associated production web page are included in Mozilla's web and services bug bounty program on HackerOne. We welcome reports from the security community and are committed to working collaboratively to investigate and resolve vulnerabilities responsibly.

Reporting a Potential Vulnerability

Please submit all security-related bugs through HackerOne. Do not submit security-related bugs through GitHub Issues, GitHub Security Advisories (GHSAs), pull requests, or email. HackerOne is where Mozilla evaluates duplicate status and coordinates disclosure and credit.

What to include

To help us triage quickly, please provide:

  • A clear description of the issue
  • Steps to reproduce, or a proof of concept
  • Affected versions, services, deployments, or environments
  • Potential impact, including what an attacker could achieve
  • Any suggested mitigations or fixes

Bug Bounty

This project is part of Mozilla's bug bounty program. Details can be found in the Mozilla program policy.

Learn more about advisories related to taskcluster/taskcluster in the GitHub Advisory Database