# What is Discourse's policy on penetration testing and reporting security bugs?

**URL:** https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004
**Category:** Site feedback
**Created:** [4월 18, 2013, 7:36오후 UTC](https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004 "2013-04-18T19:36:01Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Iszi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iszi/32/105060_2.png) [@Iszi](https://meta.discourse.org/u/Iszi)
#### Post date: [4월 18, 2013, 7:36오후 UTC](https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004/1 "2013-04-18T19:36:01Z")

</div>

Security vulnerabilities in IT systems and applications are becoming more and more of a hot topic these days. Different organizations have different policies regarding the acceptance of volunteer penetration testers’ efforts, and the submission of security vulnerability data.

While I personally do not have immediate plans to go hunting for weaknesses in the Discourse platform, I think the following questions should be answered for anyone who may.

- How does CDCK, Inc. feel about “white hat” penetration testers actively looking for vulnerabilities in the Discourse application or on servers at [try.discourse.org](http://try.discourse.org)?
- How should security vulnerabilities, whether discovered deliberately or incidentally, be reported - should they be posted to Meta.Discourse, or sent to a specific e-mail address?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [4월 18, 2013, 7:44오후 UTC](https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004/2 "2013-04-18T19:44:51Z")

</div>

Fine, test away!

Email anything you find to [team@discourse.org](mailto:team@discourse.org) – I realized we don’t actually print this email anywhere on our website proper.. oops. Will fix.

---

<div class="post-metadata">

### Author: ![jrg](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jrg/32/103725_2.png) [@jrg](https://meta.discourse.org/u/jrg)
#### Post date: [4월 28, 2013, 4:20오후 UTC](https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004/3 "2013-04-28T16:20:56Z")

</div>

At the opposite end of reporting - notifying those who’ve got Discourse running - will you set up either a “security-announce” mailing list, and/or RSS feed?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [4월 29, 2013, 5:51오전 UTC](https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004/4 "2013-04-29T05:51:44Z")

</div>

You can just follow @discourse on Twitter, anything of significance will be posted there.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [5월 19, 2014, 1:38오전 UTC](https://meta.discourse.org/t/what-is-discourses-policy-on-penetration-testing-and-reporting-security-bugs/6004/5 "2014-05-19T01:38:55Z")

</div>

There is also [security.md in the /docs folder of the project](https://github.com/discourse/discourse/blob/master/docs/SECURITY.md), which documents related security stuff.
