mirror of
https://github.com/freeCodeCamp/freeCodeCamp.git
synced 2026-05-28 18:26:54 +00:00
chore(i18n,docs): processed translations (#45787)
This commit is contained in:
@@ -1,20 +1,24 @@
|
||||
# Security Policy
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
This document outlines our security policy for the codebases, platforms that we operate, and how to report vulnerabilities.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you think you have found a vulnerability, _please report responsibly_. Don't create GitHub issues for security issues. Instead, please send an email to `security@freecodecamp.org` and we'll look into it immediately.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Ensure that you are using the **latest**, **stable** and **updated** version of the Operating System and Web Browser available to you on your machine.
|
||||
### Guidelines
|
||||
|
||||
We appreciate any responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Once you report a vulnerability, we will look into it and make sure that it is not a false positive. We will get back to you if we need to clarify any details. You can submit separate reports for each issue you find.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
### Reporting
|
||||
|
||||
We consider using tools & online utilities to report issues with SPF & DKIM configs, or SSL Server tests, etc. in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties/) and are unable to respond to these reports.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Platforms & Codebases
|
||||
|
||||
@@ -35,12 +39,16 @@ Here is a list of the platforms and codebases we are accepting reports for:
|
||||
| production | Yes | `freecodecamp.org/news` |
|
||||
| localized | Yes | `freecodecamp.org/<language>/news` |
|
||||
|
||||
### Mobile app
|
||||
### Mobile App
|
||||
|
||||
| Version | Supported | Website active |
|
||||
| ---------- | --------- | ---------------------------------------------------------------- |
|
||||
| production | Yes | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub, under the freeCodeCamp organization.
|
||||
### Other Platforms
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability please ensure that it is not a bug in the upstream software.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,20 +1,24 @@
|
||||
# Security Policy
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
This document outlines our security policy for the codebases, platforms that we operate, and how to report vulnerabilities.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you think you have found a vulnerability, _please report responsibly_. Don't create GitHub issues for security issues. Instead, please send an email to `security@freecodecamp.org` and we'll look into it immediately.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Ensure that you are using the **latest**, **stable** and **updated** version of the Operating System and Web Browser available to you on your machine.
|
||||
### Guidelines
|
||||
|
||||
We appreciate any responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Once you report a vulnerability, we will look into it and make sure that it is not a false positive. We will get back to you if we need to clarify any details. You can submit separate reports for each issue you find.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
### Reporting
|
||||
|
||||
We consider using tools & online utilities to report issues with SPF & DKIM configs, or SSL Server tests, etc. in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties/) and are unable to respond to these reports.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Platforms & Codebases
|
||||
|
||||
@@ -35,12 +39,16 @@ Here is a list of the platforms and codebases we are accepting reports for:
|
||||
| production | Yes | `freecodecamp.org/news` |
|
||||
| localized | Yes | `freecodecamp.org/<language>/news` |
|
||||
|
||||
### Mobile app
|
||||
### Mobile App
|
||||
|
||||
| Version | Supported | Website active |
|
||||
| ---------- | --------- | ---------------------------------------------------------------- |
|
||||
| production | Yes | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub, under the freeCodeCamp organization.
|
||||
### Other Platforms
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability please ensure that it is not a bug in the upstream software.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,26 +1,30 @@
|
||||
# Política de seguridad
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
Este documento describe nuestra política de seguridad para los códigos, plataformas que operamos, y cómo reportar vulnerabilidades.
|
||||
|
||||
## Informar una vulnerabilidad
|
||||
|
||||
Si crees que has encontrado una vulnerabilidad, _informa responsablemente_. No crees temas de GitHub para problemas de seguridad. En su lugar, por favor envía un correo electrónico a `security@freecodecamp.org` y lo estudiaremos inmediatamente.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Asegúrese de que está usando la **última**, **estable** y **actualizaron** versión del sistema operativo y del navegador Web disponible para usted en su máquina.
|
||||
### Guidelines
|
||||
|
||||
Apreciamos cualquier divulgación responsable de vulnerabilidades que puedan afectar la integridad de nuestras plataformas y usuarios.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Una vez que informe de una vulnerabilidad, la examinaremos y nos aseguraremos de que no sea un falso positivo. Nos pondremos en contacto con usted si necesitamos aclarar cualquier detalle. Puedes enviar informes separados para cada número que encuentres.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
Aunque no ofrecemos ninguna recompensa o swags en este momento, Estaremos encantados de listar tu nombre en nuestra lista de [Hall of Fame](security-hall-of-fame.md), siempre y cuando los informes no sean de bajo esfuerzo.
|
||||
### Reporting
|
||||
|
||||
Consideramos el uso de herramientas y utilidades en línea para informar problemas con configuraciones SPF y DKIM, o pruebas de servidor SSL, etc. en la categoría de ["recompensas"](https://www.troyhunt.com/beg-bounties/) y no pueden responder a estos informes.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Plataformas y Bases de Código
|
||||
|
||||
Aquí hay una lista de las plataformas y bases de código para las que estamos aceptando informes:
|
||||
Here is a list of the platforms and codebases we are accepting reports for:
|
||||
|
||||
### Plataforma de aprendizaje
|
||||
### Learn Platform
|
||||
|
||||
| Versión | Rama | Soportado | Sitio web activo |
|
||||
| ---------- | -------------- | --------- | ------------------------ |
|
||||
@@ -28,19 +32,23 @@ Aquí hay una lista de las plataformas y bases de código para las que estamos a
|
||||
| escenario | `prod-staging` | Sí | `freecodecamp.dev/learn` |
|
||||
| desarrollo | `principal` | No | |
|
||||
|
||||
### Plataforma de publicación
|
||||
### Publication Platform
|
||||
|
||||
| Versión | Soportado | Sitio web activo |
|
||||
| ---------- | --------- | ---------------------------------------- |
|
||||
| producción | Sí | `freecodecamp.org/news` |
|
||||
| localizado | Sí | `freecodecamp.org/<language>/news` |
|
||||
|
||||
### Aplicación Móvil
|
||||
### Mobile App
|
||||
|
||||
| Versión | Soportado | Sitio web activo |
|
||||
| ---------- | --------- | ---------------------------------------------------------------- |
|
||||
| producción | Sí | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Aparte de lo anterior, también estamos aceptando informes para repositorios alojados en GitHub, bajo la organización freeCodeCamp.
|
||||
### Other Platforms
|
||||
|
||||
Auto-alojamos algunas de nuestras plataformas utilizando software de código abierto como Ghost & Discourse. Si está reportando una vulnerabilidad, asegúrese de que no es un error en el software original.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,26 +1,30 @@
|
||||
# Sicherheitsrichtlinie
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
Dieses Dokument beschreibt unsere Sicherheitsrichtlinien für die Codebases und Plattformen, die wir betreiben, und wie du Schwachstellen melden kannst.
|
||||
|
||||
## Eine Schwachstelle melden
|
||||
|
||||
Wenn du glaubst, dass du eine Schwachstelle gefunden hast, _bitte melde sie verantwortungsvoll_. Erstelle kein GitHub-Issue für Sicherheitsprobleme. Schicke stattdessen bitte eine E-Mail an `security@freecodecamp.org` und wir werden uns sofort darum kümmern.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Stelle sicher, dass du die **neueste**, **stabilste (stable)** und **aktuellste** Version des Betriebssystems und des Webbrowsers verwendest, die dir auf deinem Computer zur Verfügung stehen.
|
||||
### Guidelines
|
||||
|
||||
Wir freuen uns über jede verantwortungsvolle Offenlegung von Schwachstellen, die die Integrität unserer Plattformen und Nutzer/innen beeinträchtigen könnten.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Wenn du eine Schwachstelle meldest, werden wir sie untersuchen und sicherstellen, dass es sich nicht um einen Fehlalarm handelt. Wir werden uns bei dir melden, wenn wir noch Details klären müssen. Du kannst für jedes Problem, das du findest, eine gesonderte Mitteilung machen.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
Im Moment bieten wir zwar keine Belohnungen oder Swags an, aber wir nehmen deinen Namen gerne in unsere [Hall of Fame](security-hall-of-fame.md)-Liste auf, vorausgesetzt, die Meldungen betreffen keine geringfügigen Probleme.
|
||||
### Reporting
|
||||
|
||||
Wir betrachten die Verwendung von Online-Tools und Hilfsprogrammen zur Meldung von Problemen mit SPF- und DKIM-Einstellungen, SSL-Server-Tests usw. als ["beg bounties"](https://www.troyhunt.com/beg-bounties/) und werden auf diese Meldungen nicht reagieren.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Plattformen & Codebasen
|
||||
|
||||
Hier ist eine Liste der Plattformen und Codebasen, für die wir Meldungen annehmen:
|
||||
Here is a list of the platforms and codebases we are accepting reports for:
|
||||
|
||||
### Lernplattform
|
||||
### Learn Platform
|
||||
|
||||
| Version | Branch | wird unterstützt | aktive Website |
|
||||
| ----------- | -------------- | ---------------- | ------------------------ |
|
||||
@@ -28,7 +32,7 @@ Hier ist eine Liste der Plattformen und Codebasen, für die wir Meldungen annehm
|
||||
| staging | `prod-staging` | Ja | `freecodecamp.dev/learn` |
|
||||
| development | `main` | Nein | |
|
||||
|
||||
### Plattform für Publikationen
|
||||
### Publication Platform
|
||||
|
||||
| Version | wird unterstützt | aktive Website |
|
||||
| ---------- | ---------------- | ---------------------------------------- |
|
||||
@@ -41,6 +45,10 @@ Hier ist eine Liste der Plattformen und Codebasen, für die wir Meldungen annehm
|
||||
| ---------- | ---------------- | ---------------------------------------------------------------- |
|
||||
| production | Ja | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Außerdem nehmen wir auch Meldungen für Repositories entgegen, die auf GitHub unter der freeCodeCamp-Organisation gehostet werden.
|
||||
### Other Platforms
|
||||
|
||||
Einige unserer Plattformen hosten wir selbst mit Open-Source-Software wie Ghost & Discourse. Wenn du eine Sicherheitslücke meldest, stelle bitte sicher, dass es sich nicht um einen Fehler in der Originalsoftware handelt.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,26 +1,30 @@
|
||||
# Politica di Sicurezza
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
Questo documento delinea la nostra politica di sicurezza per codepase, le piattaforme che operiamo, e come riportare vulnerabilità.
|
||||
|
||||
## Segnalare una vulnerabilità
|
||||
|
||||
Se pensi di aver trovato una vulnerabilità, _perfavore riportala responsabilmente_. Non creare una issue su GitHub per problemi di sicurezza. Invece invia una email a `security@freecodecamp.org` e controlleremo immediatamente.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Assicurati di star usando l'**ultima** versione **aggiornata** e **stabile** del tuo sistema operativo e del tuo browser web che ti sono disponibili sulla tua macchina.
|
||||
### Guidelines
|
||||
|
||||
Apprezziamo qualsiasi notifica responsabile di vulnerabilità che possa impattare l'integrità delle nostre piattaforme e i nostri utenti.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Una volta che riporti una vulnerabilità, la investigheremo e ci assicureremo che non sia un falso positivo. Ti risponderemo se avremo bisogno di chiarificare qualsiasi dettaglio. Puoi sottomettere report separati per ogni problema che trovi.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
Anche se non offriamo ricompense al momento, saremo felici di aggiungere il tuo nome alla lista nella [Hall of Fame](security-hall-of-fame.md), sempre che i report non siano senza sforzo.
|
||||
### Reporting
|
||||
|
||||
Consideriamo l'ultilizzo di strumenti e utiliti online per riportare problemi con le configurazioni SPF &DKIM, o test SSL Server, nella categoria ["beg bounties"](https://www.troyhunt.com/beg-bounties/) e non siamo possibilitati a rispondere a questi report.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Piattaforme & Codebase
|
||||
|
||||
Ecco una lista delle piattaforme e codebase per cui accettiamo report:
|
||||
Here is a list of the platforms and codebases we are accepting reports for:
|
||||
|
||||
### Piattaforma di apprendimento
|
||||
### Learn Platform
|
||||
|
||||
| Versione | Branch | Supportata | Website attivo |
|
||||
| ---------- | -------------- | ---------- | ------------------------ |
|
||||
@@ -28,19 +32,23 @@ Ecco una lista delle piattaforme e codebase per cui accettiamo report:
|
||||
| staging | `prod-staging` | Sì | `freecodecamp.dev/learn` |
|
||||
| sviluppo | `main` | No | |
|
||||
|
||||
### Piattaforma di pubblicazione
|
||||
### Publication Platform
|
||||
|
||||
| Versione | Supportata | Website attivo |
|
||||
| ----------- | ---------- | ---------------------------------------- |
|
||||
| production | Sì | `freecodecamp.org/news` |
|
||||
| localizzata | Sì | `freecodecamp.org/<language>/news` |
|
||||
|
||||
### App mobile
|
||||
### Mobile App
|
||||
|
||||
| Versione | Supportata | Website attivo |
|
||||
| ---------- | ---------- | ---------------------------------------------------------------- |
|
||||
| production | Sì | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Oltre queste, accettiamo report per repository ospitate su GitHub sotto l'organizzazione freeCodeCamp.
|
||||
### Other Platforms
|
||||
|
||||
Facciamo l'host noi stessi di alcune delle nostre piattaforme usando software open-source come Ghost & Discourse. Se stai riportando una vulnerabilità per favore assicurati che non sua un bug nel software a fonte.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,26 +1,30 @@
|
||||
# セキュリティポリシー
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
このドキュメントでは、コードベース、運用プラットフォーム、および脆弱性の報告方法に関するセキュリティポリシーについて概説します。
|
||||
|
||||
## 脆弱性の報告
|
||||
|
||||
脆弱性を発見したと思われる場合は、_責任を持って報告してください_。 セキュリティ問題のために GitHub Issue を作成しないでください。 その代わりに、`security@freecodecamp.org` にメールを送信してください。私たちが直ちに調査します。
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
お使いのマシンで使用できるオペレーティングシステムと Web ブラウザの **最新**、**安定**、および **更新** バージョンを使用していることを確認してください。
|
||||
### Guidelines
|
||||
|
||||
私たちのプラットフォームおよびユーザーの整合性に影響を与える可能性のある脆弱性について、責任ある開示をお願いします。
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
脆弱性が報告されたら、それを調査し誤検知ではないことを確認します。 詳細を明確にする必要がある場合は、ご連絡いたします。 発見した各問題について個別にレポートを提出することができます。
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
現時点ではいかなる報奨金も報酬も提供していませんが、その報告に多大なご尽力をいただいた場合、[殿堂入り](security-hall-of-fame.md) リストにお名前を掲示いたします。
|
||||
### Reporting
|
||||
|
||||
私たちは、[「beg bounties」](https://www.troyhunt.com/beg-bounties/) カテゴリの SPF & DKIM 構成、または SSL サーバーテスト等に関する問題を報告するため、ツール & オンラインユーティリティを使用することを検討します。それらの報告に対して対応することはできません。
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## プラットフォーム & コードベース
|
||||
|
||||
報告を受け付けるプラットフォームとコードベースのリストは以下のとおりです。
|
||||
Here is a list of the platforms and codebases we are accepting reports for:
|
||||
|
||||
### 学習プラットフォーム
|
||||
### Learn Platform
|
||||
|
||||
| バージョン | ブランチ | サポート | 有効な Web サイト |
|
||||
| ------ | -------------- | ---- | ------------------------ |
|
||||
@@ -28,19 +32,23 @@
|
||||
| ステージング | `prod-staging` | 有 | `freecodecamp.dev/learn` |
|
||||
| 開発 | `main` | 無 | |
|
||||
|
||||
### 公開プラットフォーム
|
||||
### Publication Platform
|
||||
|
||||
| バージョン | サポート | 有効な Web サイト |
|
||||
| ------ | ---- | ---------------------------------------- |
|
||||
| 本番 | 有 | `freecodecamp.org/news` |
|
||||
| ローカライズ | 有 | `freecodecamp.org/<language>/news` |
|
||||
|
||||
### モバイルアプリ
|
||||
### Mobile App
|
||||
|
||||
| バージョン | サポート | 有効な Web サイト |
|
||||
| ----- | ---- | ---------------------------------------------------------------- |
|
||||
| 本番 | 有 | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
上記とは別に、freeCodeCamp 組織で、GitHub にホストされているリポジトリの報告も受け付けています。
|
||||
### Other Platforms
|
||||
|
||||
Ghost & Discourse のようなオープンソースソフトウェアを使用して、いくつかのプラットフォームをセルフホストします。 脆弱性を報告する場合は、アップストリームソフトウェアのバグではないことを確認してください。
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,26 +1,30 @@
|
||||
# Política de segurança
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
Este documento descreve a nossa política de segurança para as bases de código, para as plataformas que operamos, além de mostrar como relatar vulnerabilidades.
|
||||
|
||||
## Relatando uma vulnerabilidade
|
||||
|
||||
Se você acha que encontrou uma vulnerabilidade, _reporte-a de modo responsável_. Não crie issues no GitHub para problemas de segurança. Em vez disso, envie um e-mail para `security@freecodecamp.org` e investigaremos isso imediatamente.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Certifique-se de estar usando a versão **mais recente**, **estável** e **atualizada** do sistema operacional e do navegador da web disponível para você em sua máquina.
|
||||
### Guidelines
|
||||
|
||||
Apreciamos qualquer divulgação responsável de vulnerabilidades que possa impactar a integridade de nossas plataformas e usuários.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Ao reportar uma vulnerabilidade, vamos analisá-la e garantir que ela não é um falso positivo. Voltaremos a entrar em contato, caso seja necessário esclarecer alguns detalhes. Você pode enviar relatórios separados para cada issue que encontrar.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
Embora não possamos oferecer nenhuma recompensa ou troca no momento, ficaremos felizes em listar seu nome em nossa [Lista dos famosos](security-hall-of-fame.md), contanto que os relatórios não sejam de baixo esforço.
|
||||
### Reporting
|
||||
|
||||
Consideramos o uso de ferramentas e utilitários on-line para relatar issues com SPF e configurações DKIM, testes de servidor SSL etc. na categoria de ["recompensas por migalhas"](https://www.troyhunt.com/beg-bounties/) e não responderemos a estes relatórios.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Plataformas e bases de código
|
||||
|
||||
Aqui está uma lista das plataformas e bases de código para as quais estamos aceitando relatórios:
|
||||
Here is a list of the platforms and codebases we are accepting reports for:
|
||||
|
||||
### Plataforma de aprendizagem
|
||||
### Learn Platform
|
||||
|
||||
| Versão | Branch | Suportado | Site da web ativo |
|
||||
| --------------- | -------------- | --------- | ------------------------ |
|
||||
@@ -28,19 +32,23 @@ Aqui está uma lista das plataformas e bases de código para as quais estamos ac
|
||||
| staging | `prod-staging` | Sim | `freecodecamp.dev/learn` |
|
||||
| desenvolvimento | `main` | Não | |
|
||||
|
||||
### Plataforma de publicação
|
||||
### Publication Platform
|
||||
|
||||
| Versão | Suportado | Site da web ativo |
|
||||
| ---------- | --------- | -------------------------------------- |
|
||||
| produção | Sim | `freecodecamp.org/news` |
|
||||
| localizado | Sim | `freecodecamp.org/<idioma>/news` |
|
||||
|
||||
### Aplicativo móvel
|
||||
### Mobile App
|
||||
|
||||
| Versão | Suportado | Site da web ativo |
|
||||
| -------- | --------- | ---------------------------------------------------------------- |
|
||||
| produção | Sim | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Além dos itens acima, também aceitamos relatórios para repositórios hospedados no GitHub, da organização do freeCodeCamp.
|
||||
### Other Platforms
|
||||
|
||||
Hospedamos algumas de nossas próprias plataformas usando softwares de código aberto, como o Ghost e o Discourse. Se você está relatando uma vulnerabilidade, certifique-se de que não é um erro no software do upstream.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
@@ -1,20 +1,24 @@
|
||||
# Security Policy
|
||||
# freeCodeCamp.org's Security Policy
|
||||
|
||||
This document outlines our security policy for the codebases, platforms that we operate, and how to report vulnerabilities.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you think you have found a vulnerability, _please report responsibly_. Don't create GitHub issues for security issues. Instead, please send an email to `security@freecodecamp.org` and we'll look into it immediately.
|
||||
> [!NOTE] If you think you have found a vulnerability, **please report it responsibly**. Do not create GitHub issues for security issues. Instead, follow this guide.
|
||||
|
||||
Ensure that you are using the **latest**, **stable** and **updated** version of the Operating System and Web Browser available to you on your machine.
|
||||
### Guidelines
|
||||
|
||||
We appreciate any responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users.
|
||||
We appreciate responsible disclosure of vulnerabilities that might impact the integrity of our platforms and users. In the interest of saving everyone time, we encourage you to report vulnerabilities with these in mind:
|
||||
|
||||
Once you report a vulnerability, we will look into it and make sure that it is not a false positive. We will get back to you if we need to clarify any details. You can submit separate reports for each issue you find.
|
||||
1. Ensure that you are using the **latest**, **stable**, and **updated** versions of the Operating System and Web Browser(s) available to you on your machine.
|
||||
2. We consider using tools & online utilities to report issues with SPF & DKIM configs, SSL Server tests, etc., in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties) and are unable to respond to these reports.
|
||||
3. While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
|
||||
While we do not offer any bounties or swags at the moment, we'll be happy to list your name in our [Hall of Fame](security-hall-of-fame.md) list, provided the reports are not low-effort.
|
||||
### Reporting
|
||||
|
||||
We consider using tools & online utilities to report issues with SPF & DKIM configs, or SSL Server tests, etc. in the category of ["beg bounties"](https://www.troyhunt.com/beg-bounties/) and are unable to respond to these reports.
|
||||
After confirming the above guidelines, please feel free to send an email to `possible-security-issue [at] freecodecamp.org`. You can also send us a PGP encrypted message at `flowcrypt.com/me/freecodecamp`.
|
||||
|
||||
Once you report a vulnerability, we will look into it and ensure that it is not a false positive. If we need to clarify any details, we will get back to you. You can submit separate reports for each issue you find. Please note that we will not be able to respond to any issues that we think are outside the guidelines.
|
||||
|
||||
## Platforms & Codebases
|
||||
|
||||
@@ -35,12 +39,16 @@ Here is a list of the platforms and codebases we are accepting reports for:
|
||||
| production | Yes | `freecodecamp.org/news` |
|
||||
| localized | Yes | `freecodecamp.org/<language>/news` |
|
||||
|
||||
### Mobile app
|
||||
### Mobile App
|
||||
|
||||
| Version | Supported | Website active |
|
||||
| ---------- | --------- | ---------------------------------------------------------------- |
|
||||
| production | Yes | `https://play.google.com/store/apps/details?id=org.freecodecamp` |
|
||||
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub, under the freeCodeCamp organization.
|
||||
### Other Platforms
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability please ensure that it is not a bug in the upstream software.
|
||||
Apart from the above, we are also accepting reports for repositories hosted on GitHub under the freeCodeCamp organization.
|
||||
|
||||
### Other Self-hosted Applications
|
||||
|
||||
We self-host some of our platforms using open-source software like Ghost & Discourse. If you are reporting a vulnerability, please ensure that it is not a bug in the upstream software.
|
||||
|
||||
Reference in New Issue
Block a user