Skip to content

Commit 48a0685

Browse files
committed
added info for informative and spam reports for program report states
1 parent 94c1a2d commit 48a0685

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

docs/programs/report-states.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ State | Details
1414
----- | ------
1515
Pre-submission | This report state is only applicable when Human-Augmented Signal is enabled for the program. The report starts in the pre-submission state when it has been flagged as potentially invalid. A HackerOne security analyst will first review the report before it's sent to the program.
1616
New | The report is in an unread state.
17-
Pending Program Review | *(Currently in beta)* The report has been reviewed by HackerOne triage and is now pending review from the program. This only shows for programs that use HackerOne's triage services.
17+
Pending Program Review | *(Currently in beta)* The report has been reviewed by HackerOne triage and is now pending review from the program. This only shows for programs that use HackerOne's triage services.
1818
Triaged | The report is evaluated but hasn't been resolved. It's in the state of being fixed.
1919
Retesting | The vulnerability is in the process of being [retested](retesting.html).
2020
Needs More Info | More information is needed from the hacker about the vulnerability. Reports that are in the *Needs More Info* state for more than 30 days will automatically close and won't have a negative impact on the hacker's reputation.
@@ -30,7 +30,7 @@ These are the Closed report states:
3030
State | Details | Change to Hacker Reputation
3131
----- | ------ | ----------------------------
3232
Resolved | The report is valid, and no further dialogue with the hacker is needed. | Increase +7
33-
Informative | The report contains useful information but doesn't warrant an immediate action or a fix. Your program can consider providing an alternative risk assessment or other mitigating factors, and public disclosure is available with mutual agreement. | No change
33+
Informative | The report contains useful information but doesn't warrant immediate action or a fix. Examples of informative reports include:<ul><li>Notifications of broken links</li><li>The issue is not consistently reproducible</li><li>The hacker reports a subdomain takeover they encountered but didn't execute it themselves</li></ul> Your program can consider providing an alternative risk assessment or other mitigating factors, and public disclosure is available with mutual agreement. | No change
3434
Duplicate | This issue has already been reported. Programs can build trust by attributing the issue to its original discoverer and linking it to a previous report or including other details about its discovery. Public disclosure is not available for this state. <br>*Note: If a hacker files a duplicate or public report, their reputation will go down.* | If the hacker submits the original report:<br>*Resolved*: +2 <br><br><br>*Not Applicable*: -5 <br><br>*Informative*: 0
3535
Not Applicable | The report doesn't contain a valid issue and has no security implications. Security teams should describe why the report was invalid so the hacker can improve their hacking skills. | Decrease -5
36-
Spam | The report is invalid because the hacker didn't describe a legitimate security vulnerability. You should notify HackerOne so additional restrictions can be applied to the hacker. | Decrease -10
36+
Spam | The report is invalid because the hacker didn't describe a legitimate security vulnerability. The report may be incomprehensible, abusive and/or exhibit harassment. Reports that sell any sort of product or service will also be marked as Spam. You should notify HackerOne when you encounter Spam so that additional restrictions can be applied to the hacker. | Decrease -10

0 commit comments

Comments
 (0)