Skip to content

Commit 47c3ea0

Browse files
adamjonasryanofsky
andcommitted
doc: add OSS-Fuzz section to fuzzing.md doc
Co-authored-by: Russell Yanofsky <[email protected]>
1 parent 3f8f238 commit 47c3ea0

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

doc/fuzzing.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -230,3 +230,15 @@ $ honggfuzz/honggfuzz --exit_upon_crash --quiet --timeout 4 -n 1 -Q \
230230
-nodebuglogfile -bind=127.0.0.1:18444 -logthreadnames \
231231
-debug
232232
```
233+
234+
# OSS-Fuzz
235+
236+
Bitcoin Core participates in Google's [OSS-Fuzz](https://github.com/google/oss-fuzz/tree/master/projects/bitcoin-core)
237+
program, which includes a dashboard of [publicly disclosed vulnerabilities](https://bugs.chromium.org/p/oss-fuzz/issues/list).
238+
Generally, we try to disclose vulnerabilities as soon as possible after they
239+
are fixed to give users the knowledge they need to be protected. However,
240+
because Bitcoin is a live P2P network, and not just standalone local software,
241+
we might not fully disclose every issue within Google's standard
242+
[90-day disclosure window](https://google.github.io/oss-fuzz/getting-started/bug-disclosure-guidelines/)
243+
if a partial or delayed disclosure is important to protect users or the
244+
function of the network.

0 commit comments

Comments
 (0)