Skip to content

docs(RMT-2581): Clarify VDP reward policy and eligibility#7165

Merged
jpe442 merged 1 commit into
developfrom
vdp-update-RMT-2581
May 7, 2026
Merged

docs(RMT-2581): Clarify VDP reward policy and eligibility#7165
jpe442 merged 1 commit into
developfrom
vdp-update-RMT-2581

Conversation

@nicksalvemini-edb
Copy link
Copy Markdown
Contributor

Added specificity around what qualifies as a "previously unknown" vulnerability and the criteria for former EDB employee submissions.

@nicksalvemini-edb nicksalvemini-edb requested a review from a team as a code owner May 7, 2026 17:08
@jpe442 jpe442 merged commit f9bb432 into develop May 7, 2026
12 checks passed
@jpe442 jpe442 deleted the vdp-update-RMT-2581 branch May 7, 2026 17:40

### Eligibility

We welcome reports from anyone who believes they have identified a vulnerability impacting EnterpriseDB, including current and former employees, contractors, customers, partners, and members of the wider security and PostgreSQL communities. Safe harbor under this policy applies to all good-faith submissions, regardless of the reporter's relationship to EDB.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nicksalvemini-edb - you probably should to remove "current and former employees" from here for clarity and it contradicts the bullet below.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TY for feedback - not opposed to making this change, but I want to clarify: I'm not sure they contradict, the point is to specify that submissions are eligible from anyone, but rewards have different criteria.

L66: "Reward eligibility, however, is more limited:"

And then specify criteria etc.

TLDR I was trying to specify the difference in those claims; ALL (including current/former employees) are welcome to submit, but rewards are limited for EDB employees.

Thoughts?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants