Skip to content

Point the security policy at the Cantina bug bounty - #739

Merged
lukasz-zimnoch merged 1 commit into
mainfrom
security-cantina-bounty
Sep 23, 2026
Merged

lukasz-zimnoch merged 1 commit into
mainfrom
security-cantina-bounty

Conversation

@Shadowfiend

Copy link
Copy Markdown
Contributor

Mezo now runs a bug bounty on Cantina. Report volume from LLM agents has made unfiltered email triage unsustainable, so:

  • In-scope findings go through Cantina, which is required for a reward.
  • security@mezo.org is reserved for high-severity, highly exploitable, time-sensitive issues. Other email reports may get no response.
  • The best-effort response time for qualifying email reports is now 24 hours (was 48).

This keeps the existing wording about secure channels such as Signal. It adds a note that mezod is in the bounty's scope and links to https://mezo.org/SECURITY.md for the full reporting guidelines instead of duplicating them.

🤖 Generated with Claude Code

Mezo now runs a bug bounty on Cantina, which replaces the old
"source a bounty case by case" approach. Report volume from LLM
agents has made unfiltered email triage unsustainable, so email is
reserved for high-severity, highly exploitable, time-sensitive
issues, with a 24-hour best-effort response. Everything else goes
through Cantina.

The full reporting guidelines now live at mezo.org/SECURITY.md; this
file links there rather than duplicating them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lukasz-zimnoch
lukasz-zimnoch merged commit a5b390c into main Sep 23, 2026
5 of 8 checks passed
@lukasz-zimnoch
lukasz-zimnoch deleted the security-cantina-bounty branch September 23, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants