[9.20] chg: doc: Add text about no bug bounties

Vicky and Ondrej have agreed that we should add text to explain that we do not give bug bounties.

Backport of MR !10246

Merge branch 'backport-sgoldlust-main-bug-bounty-9.20' into 'bind-9.20'

See merge request isc-projects/bind9!10527
This commit is contained in:
Petr Špaček 2025-06-02 07:11:11 +00:00
commit 3471c8a2b5

View file

@ -32,6 +32,14 @@ responsible reporters.
If you have a crash, you may want to consult the Knowledgebase article
entitled ["What to do if your BIND or DHCP server has crashed"][3].
## Reporting bugs
We are working with the interests of the greater Internet at heart, and
we hope you are too. In that vein, we do not offer bug bounties. If you
think you have found a bug in any ISC software, we encourage you to
[report it responsibly][2]; if verified, we will be happy to credit you
in our Release Notes.
[1]: https://kb.isc.org/docs/aa-00861
[2]: https://gitlab.isc.org/isc-projects/bind9/-/issues/new?description_template=Security_issue
[2]: https://gitlab.isc.org/isc-projects/bind9/-/issues/new?issue[confidential]=true&issuable_template=Security_issue
[3]: https://kb.isc.org/docs/aa-00340