google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
869 stars 176 forks source link

**PLEASE READ BEFORE PRP REQUEST**: Notes to Patch Reward Program Participants #68

Open magl0 opened 2 years ago

magl0 commented 2 years ago

First of all, thanks everyone for your interest in this new patch reward program! 40+ requests in less than 24 hours are totally unexpected :)

The Tsunami Scanner Team would like to post several notes for both existing users and newcomers of the program:

And regarding the plugin contributions:

maoning commented 1 year ago

Please run https://github.com/google/google-java-format against your Java files before starting the code review, this would greatly reduce review overhead due to linter errors.

maoning commented 4 months ago

Since last year we have made the following changes to the program to make it more sustainable and to support our contributors better:

PR Review Throughput

We are partnering with Doyensec to share the plugin review workload. They have been carefully vested and onboarded to the Tsunami ecosystem in the past 6 months. Some of you will start receiving review feedback from Doyensec members starting this week.

Plugin Contribution Opportunities

We have recently released a set of AI relevant Tsunami plugin requests (blog post, github label) to offer more plugin contribution opportunities to the community. We will continue doing so and welcome new plugin requests in the AI space.

Consistent Submission & Review Process

To make the review process more consistent & easier to do long-term test and debug, for new PRs, please submit your secure and insecure application configurations to the security-testbeds repo first. We also have more exciting plans for security-testbeds, stay tuned for future updates.