We're a core blockchain infrastructure company. We're creating an open-source creative commons that will enable people to create better institutions through technology.
Target | Type | Severity | Reward |
---|---|---|---|
Parity Releases Pipeline Copy Parity Releases Pipeline: any bugs which could be used to enable an attacker to inject malicious code into our distributed binaries, or be used to halt Parity's release process or add malicious/unintended functions to the released binaries. | Code | High | Bounty |
Production infrastructure Copy Production infrastructure: publicly available infrastructure Parity runs for production-grade networks (in contrast to testnets), especially parts which are critical for a network's well-being or safety of funds. Please note that this does not include our publicly available web pages. | Web | None | Bounty |
Parity Releases Pipeline: any bugs which could be used to enable an attacker to inject malicious code into our distributed binaries, or be used to halt Parity's release process or add malicious/unintended functions to the released binaries.
Production infrastructure: publicly available infrastructure Parity runs for production-grade networks (in contrast to testnets), especially parts which are critical for a network's well-being or safety of funds. Please note that this does not include our publicly available web pages.
Please note that where the scope of this policy includes third-party code this should not be taken as an indication that we are legally or otherwise responsible for that code, its security, quality or your rights in respect of that code.
Most other things are not in scope, though. Specifically:
Responsible investigation and reporting includes, but isn't limited to, the following:
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: