Skip to content

Commit e4e5bf7

Browse files
yousreedloden
authored andcommitted
ko: follow changes of security.md
1 parent 78ee1ce commit e4e5bf7

1 file changed

Lines changed: 54 additions & 28 deletions

File tree

locale/ko/security.md

Lines changed: 54 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -6,44 +6,70 @@ title: 보안
66
<!--
77
# Security
88
9-
## Reporting a Bug
9+
## Reporting a Bug in Node.js
1010
11-
All security bugs in Node.js are taken seriously and should be reported by emailing [security@nodejs.org](mailto:security@nodejs.org).
12-
This will be delivered to a subset of the core team who handle security issues.
11+
Report security bugs in Node.js via [HackerOne](https://hackerone.com/nodejs).
1312
14-
Your email will be acknowledged within 24 hours, and you’ll receive a more detailed response to your email within 48
15-
hours indicating the next steps in handling your report.
13+
Your report will be acknowledged within 24 hours, and you’ll receive a more detailed response to your report within 48
14+
hours indicating the next steps in handling your submission.
1615
-->
16+
1717
# 보안
1818

19-
# 버그 보고
19+
# Node.js 버그 보고
2020

21-
Node.js의 모든 보안 버그는 심각한 문제이므로
22-
[security@nodejs.org](mailto:security@nodejs.org) 이메일로 보고해야 합니다.
23-
이 이메일은 보안 이슈를 처리하는 코어 팀 내의 사람들에게 보내질 것입니다.
21+
Node.js의 보안 버그는 [HackerOne](https://hackerone.com/nodejs)을 통해
22+
보고해주시기 바랍니다.
2423

25-
보고된 내용은 24시간 이내에 승인하고 48시간 이내에 다음 처리 단계를 안내하는
26-
자세한 내용을 응답할 것입니다.
24+
보고된 내용은 24시간 이내에 확인될 것이고, 48시간 이내에 다음 처리 단계를
25+
안내하는 자세한 답변을 받게 될 것입니다.
2726

2827
<!--
2928
After the initial reply to your report, the security team will endeavor to keep you informed of the progress being made
3029
towards a fix and full announcement, and may ask for additional information or guidance surrounding the reported issue.
31-
These updates will be sent at least every five days, in practice, this is more likely to be every 24-48 hours.
32-
33-
Security bugs in third party modules should be reported to their respective maintainers and can also be coordinated
34-
through the [Node Security Project](https://nodesecurity.io).
35-
36-
Thank you for improving the security of Node.js. Your efforts and responsible disclosure are greatly appreciated and
37-
will be acknowledged.
30+
These updates will be sent at least every five days; in practice, this is more likely to be every 24-48 hours.
3831
-->
32+
3933
보고한 내용에 첫 답변을 한 후 보안 팀은 수정사항과 전체 공지를 만드는 과정을 보고자에게 계속 알려주려고
4034
노력할 것입니다. 보고된 이슈에 대한 추가 정보나 안내를 물어볼 수도 있습니다. 이러한 진행사항은
41-
최소 5일마다 계속 알려줄 것입니다만 실제로는 24~48시간 마다 알려줄 가능성이 큽니다.
35+
최소 5일마다 계속 알려줄 것입니다만 실제로는 24~48시간마다 알려줄 가능성이 큽니다.
36+
37+
<!--
38+
### Node.js Bug Bounty Program
39+
40+
The Node.js project engages in an official bug bounty program for security researchers and responsible public disclosures.
41+
42+
The program is managed through the HackerOne platform at <https://hackerone.com/nodejs> with further details.
43+
-->
44+
45+
### Node.js 버그 바운티 프로그램
46+
47+
Node.js 프로젝트는 보안 연구자와 책임 있는 공개를 위해 공식 버그 바운티 프로그램에 참여합니다.
4248

43-
서드파티 모듈의 보안 버그는 각 메인테이너에게 보고해야 하고
44-
[Node 보안 프로젝트](https://nodesecurity.io)를 통해 조정할 수도 있습니다.
49+
이 프로그램은 HackerOne 플랫폼을 통해 관리되며, 자세한 사항은
50+
<https://hackerone.com/nodejs>에서 확인하실 수 있습니다.
4551

46-
Node.js의 보안을 개선하게 해 준 것에 감사드립니다. 당신이 들인 노력과 책임 있는 공개에 아주
52+
<!--
53+
## Reporting a Bug in a third party module
54+
55+
Security bugs in third party modules should be reported to their respective maintainers and should also be coordinated
56+
through the Node Ecosystem Security Team via [HackerOne](https://hackerone.com/nodejs-ecosystem).
57+
58+
Details regarding this process can be found in the [Security Working Group repository](https://github.com/nodejs/security-wg/blob/master/processes/third_party_vuln_process.md).
59+
60+
Thank you for improving the security of Node.js and its ecosystem. Your efforts and responsible disclosure are greatly
61+
appreciated and will be acknowledged.
62+
-->
63+
64+
## 서드 파티 모듈의 버그 제보하기
65+
66+
서드 파티 모듈의 보안 버그는 각 메인테이너에게 보고해야 하고
67+
[HackerOne](https://hackerone.com/nodejs-ecosystem)의 Node 생태계 보안 팀을 통해 조정되어야 합니다.
68+
69+
절차에 관한 자세한 사항은 [보안 워킹 그룹 저장소](https://github.com/nodejs/security-wg/blob/master/processes/third_party_vuln_process.md)에서
70+
보실 수 있습니다.
71+
72+
Node.js와 Node.js 생태계의 보안을 개선해주셔서 감사드립니다. 당신이 들인 노력과 책임 있는 공개에 아주
4773
감사드리고 이는 인정받을 것입니다.
4874

4975
<!--
@@ -56,7 +82,7 @@ process. The problem is confirmed and a list of all affected versions is determi
5682
potential similar problems. Fixes are prepared for all releases which are still under maintenance. These fixes are not
5783
committed to the public repository but rather held locally pending the announcement.
5884
59-
- A suggested embargo date for this vulnerability is chosen and a CVE (Common Vulnerabilities and Exposures (CVE®))
85+
- A suggested embargo date for this vulnerability is chosen and a CVE (Common Vulnerabilities and Exposures (CVE®))
6086
is requested for the vulnerability.
6187
6288
- On the embargo date, the Node.js security mailing list is sent a copy of the announcement. The changes are pushed to
@@ -67,7 +93,7 @@ copy of the advisory will be published on the Node.js blog.
6793
the severity of the bug or difficulty in applying a fix.
6894
6995
- This process can take some time, especially when coordination is required with maintainers of other projects. Every
70-
effort will be made to handle the bug in as timely a manner as possible, however, it’s important that we follow the
96+
effort will be made to handle the bug in as timely a manner as possible; however, it’s important that we follow the
7197
release process above to ensure that the disclosure is handled in a consistent manner.
7298
-->
7399

@@ -99,8 +125,8 @@ release process above to ensure that the disclosure is handled in a consistent m
99125
100126
Security notifications will be distributed via the following methods.
101127
102-
- [https://groups.google.com/group/nodejs-sec](https://groups.google.com/group/nodejs-sec)
103-
- [https://nodejs.org/en/blog](https://nodejs.org/en/blog)
128+
- <https://groups.google.com/group/nodejs-sec>
129+
- <https://nodejs.org/en/blog>
104130
-->
105131

106132
## 보안 업데이트 받기
@@ -114,10 +140,10 @@ Security notifications will be distributed via the following methods.
114140
## Comments on this Policy
115141
116142
If you have suggestions on how this process could be improved please submit a [pull request](https://github.com/nodejs/nodejs.org)
117-
or email [security@nodejs.org](mailto:security@nodejs.org) to discuss.
143+
or [file an issue](https://github.com/nodejs/security-wg/issues/new) to discuss.
118144
-->
119145

120146
## 이 정책에 대한 의견
121147

122148
이 절차를 개선하기 위한 의견이 있다면 논의를 위해 [풀 리퀘스트](https://github.com/nodejs/nodejs.org)를 올리거나
123-
[security@nodejs.org](mailto:security@nodejs.org)로 이메일을 보내주시기 바랍니다.
149+
[이슈를 생성](https://github.com/nodejs/security-wg/issues/new)해주시기 바랍니다.

0 commit comments

Comments
 (0)