Skip to content

SocketDev/security-research

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Socket Security Research

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Socket which impact non-Socket owned code.

We believe that vulnerability disclosure is a two-way street. Vendors, as well as researchers, must act responsibly. This is why Socket adheres to a 90-day disclosure deadline. We notify vendors of vulnerabilities immediately, with details shared in public with the defensive community after 90 days, or sooner if the vendor releases a fix.

You can read up on our full policy at: https://socket.dev/security/outbound_vulnerability_disclosure.

Advisories

The disclosure of vulnerabilities are all in the form of security advisories, which can be browsed in the Security Advisories page.

License & Patents

The advisories and patches posted here are free and open source.

See LICENSE for further details.

Contributing

The easiest way to contribute to our security research projects is to correct the patches when you see mistakes.

Inspiration

This repository was inspired by Google/security-research.

About

No description, website, or topics provided.

Resources

License

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published