From ddbd04f3952f19376215947506646ccc170032a3 Mon Sep 17 00:00:00 2001 From: Bhargavi Rao Date: Wed, 23 Sep 2026 15:48:36 -0700 Subject: [PATCH 1/2] docs: add security policy --- SECURITY.md | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..c573ceb6 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,24 @@ +# Security Policy + +## Reporting a Vulnerability + +BitGo takes the security of its open-source software seriously. + +If you discover a security vulnerability in a public BitGo repository, please do not report it through a public GitHub issue, discussion, or pull request. + +Please report it privately by emailing **security@bitgo.com** and include: + +- The affected repository, version, or commit +- A description of the vulnerability and its potential impact +- Steps to reproduce the issue +- Any relevant proof-of-concept material + +Please do not include credentials, private keys, or other sensitive information in the initial email. The BitGo Security team can arrange a secure transfer method if additional materials are required. + +Some BitGo products and repositories may be covered by our public Bugcrowd program. Eligibility, scope, and reward requirements are determined by the program terms: + +https://bugcrowd.com/engagements/bitgo-mbb-og-public + +Please allow the BitGo Security team a reasonable opportunity to investigate and address the issue before making any public disclosure. + +Thank you for helping keep BitGo and its users secure. From 42d101f16251f8b487977db5ed2c1e3abb276b65 Mon Sep 17 00:00:00 2001 From: Bhargavi Rao Date: Wed, 30 Sep 2026 19:02:19 -0700 Subject: [PATCH 2/2] chore: format security policy --- SECURITY.md | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index c573ceb6..0d81c6a2 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -4,7 +4,8 @@ BitGo takes the security of its open-source software seriously. -If you discover a security vulnerability in a public BitGo repository, please do not report it through a public GitHub issue, discussion, or pull request. +If you discover a security vulnerability in a public BitGo repository, please do not +report it through a public GitHub issue, discussion, or pull request. Please report it privately by emailing **security@bitgo.com** and include: @@ -13,12 +14,16 @@ Please report it privately by emailing **security@bitgo.com** and include: - Steps to reproduce the issue - Any relevant proof-of-concept material -Please do not include credentials, private keys, or other sensitive information in the initial email. The BitGo Security team can arrange a secure transfer method if additional materials are required. +Please do not include credentials, private keys, or other sensitive information in the +initial email. The BitGo Security team can arrange a secure transfer method if +additional materials are required. -Some BitGo products and repositories may be covered by our public Bugcrowd program. Eligibility, scope, and reward requirements are determined by the program terms: +Some BitGo products and repositories may be covered by our public Bugcrowd program. +Eligibility, scope, and reward requirements are determined by the program terms: https://bugcrowd.com/engagements/bitgo-mbb-og-public -Please allow the BitGo Security team a reasonable opportunity to investigate and address the issue before making any public disclosure. +Please allow the BitGo Security team a reasonable opportunity to investigate and address +the issue before making any public disclosure. Thank you for helping keep BitGo and its users secure.