Skip to content

Commit

Permalink
Add SensitiveParameter attribute in the security hardening list
Browse files Browse the repository at this point in the history
  • Loading branch information
fabpot committed Dec 9, 2022
1 parent c194f5c commit 4cfa2ce
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions contributing/code/security.rst
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,8 @@ email for confirmation):
is set to ``true`` or ``APP_ENV`` set to anything but ``prod``);

* Any fix that can be classified as **security hardening** like route
enumeration, login throttling bypasses, denial of service attacks, or timing
attacks.
enumeration, login throttling bypasses, denial of service attacks, timing
attacks, or lack of ``SensitiveParameter`` attributes.

In any case, the core team has the final decision on which issues are
considered security vulnerabilities.
Expand Down

0 comments on commit 4cfa2ce

Please sign in to comment.