Skip to content

Commit 1112eb4

Browse files
authored
Update apps/site/pages/en/blog/vulnerability/march-2025-ci-incident.md
Signed-off-by: Matteo Collina <[email protected]>
1 parent 6375469 commit 1112eb4

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

apps/site/pages/en/blog/vulnerability/march-2025-ci-incident.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ The existing CI system design anticipates potential compromises, recognizing the
6363

6464
## Volunteer Organization
6565

66-
As a volunteer-driven organization, such security incidents significantly disrupt our operational capabilities. We **strongly recommend** that security researchers **avoid** unauthorized attempts to breach our systems. Instead, please coordinate responsibly through our official HackerOne program.
66+
As a volunteer-driven organization, we rely on people dedicating their time to work on unglamorous tasks, such as hardening CI, handling security reports, and assembling releases. Even good-faith research against our live systems could significantly disrupt our operations. As always, we welcome all sorts of contributions, including penetration testing. We ask researchers to give us a heads up on what they are attempting to do on live systems and to keep an auditable record of their actions through our HackerOne program or by contacting the Node.js Technical Steering Committee directly ([email protected]). More on that in our [SECURITY.md](https://github.com/nodejs/node/blob/main/SECURITY.md) file.
6767

6868
---
6969

0 commit comments

Comments
 (0)