Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

**PLEASE READ**: AI-related plugins rules of engagement #409

Open
maoning opened this issue Mar 18, 2024 · 0 comments
Open

**PLEASE READ**: AI-related plugins rules of engagement #409

maoning opened this issue Mar 18, 2024 · 0 comments

Comments

@maoning
Copy link
Collaborator

maoning commented Mar 18, 2024

In this issue tracker, you will find a list of AI-relevant plugin & web fingerprint implementation requests tagged as "help wanted". Anyone can contribute to a Tsunami plugin from this list, and the implementation will be reviewed & rewarded under our Tsunami Patch Rewards program, with rewards ranging from $500 to $3,133.7 (details).

Here are the rules of engagement for implementing AI-related plugins:

  • First come, first served: Each contributor can pick up any of the unassigned plugins, but please only take one at a time.
  • Reassignment of inactive plugins: If an assigned plugin has not been worked on for over a week, then the Tsunami review panel will unassign the contributor from the plugin. The plugin request is returned to the free-for-all pool.
  • Vulnerability Research: As a first step, the contributor has to provide detailed vulnerability research & an implementation design for the plugin to the review panel, and then wait for confirmation from the review panel before moving on to the implementation stage.
  • Testbed Requirement: All test containers or configurations for each plugin have to be submitted to google/security-testbeds.
  • Review Priority: If a contributor already has a different plugin in the review queue, we will prioritize reviewing the ML plugin, unless the originally provided plugin is critical.

You are welcome to propose new plugins that address critical security issues in AI-serving frameworks and related tools as well. For faster acceptance, when sharing your proposal, please provide context on how a given service is used in the AI ecosystem.

@maoning maoning pinned this issue Mar 18, 2024
@maoning maoning changed the title **PLEASE READ**: Rules of engagement for implementing AI-related plugins **PLEASE READ**: AI-related plugins rules of engagement Mar 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants