Skip to content

Security: mozilla/extension-workshop

SECURITY.md

Overview

We welcome reports from the security community and are committed to working collaboratively to investigate and resolve vulnerabilities responsibly.


Reporting a Potential Vulnerability

If you find a security vulnerability please submit details through Bugzilla. Always submit potential security vulnerabilities via the webform; never submit security-related bugs through a Github Issue or by email.

addons.mozilla.org (AMO)

If your security vulnerability is potentially exploitable via AMO, you may be eligible for our bug bounty program [FAQ].

What to include

To help us triage quickly, please provide:

  • A clear description of the issue
  • Steps to reproduce (or a proof of concept)
  • Affected versions / environments
  • Potential impact (what an attacker could achieve)
  • Any suggested mitigations or fixes

Non-security bugs

Other bugs, that have no potential security implications, can be submitted via the issue tracker.

There aren't any published security advisories