mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-06 02:48:04 +00:00
Remove Rule 14 (One Vulnerability Per Report)
The one-CVE-per-vulnerability constraint it restated is a CVE Program counting rule, already binding through the "Alignment with the CVE Program" section. Dropping the standalone rule removes the duplication; bundled reports are still split on that basis when they arise. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
c1e75dcdbc
commit
d06f01d237
1 changed files with 0 additions and 2 deletions
|
|
@ -144,8 +144,6 @@ Your remediation guidance can include, for example:
|
|||
>
|
||||
> If the same action also affects another user, the operator, the host system, or shared resources, identify that second party clearly in the PoC, and we want to hear about it.
|
||||
|
||||
14. **One Vulnerability Per Report:** Each report must describe a **single vulnerability**. If you have found multiple **distinct** vulnerabilities, file them as **separate reports** — one per vulnerability. A CVE identifier maps to exactly one vulnerability, so a single report bundling two or more distinct flaws **cannot be assigned a CVE** even when the individual findings are valid; GitHub will decline the CVE request. Bundling therefore actively prevents us from crediting and publishing your work.
|
||||
|
||||
**Non-compliant submissions may be closed, and repeat or extreme violators may be banned from submitting reports.** Our goal is to foster a constructive reporting environment where quality submissions promote better security for all users.
|
||||
If you want to report something that does not fulfill our rules and guidelines laid out here, you can still report it and we will handle it, [see our good faith reporting section for more information](#good-faith-reports-that-arent-vulnerabilities).
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue