Skip to content

Commit fe48769

Browse files
achesinDexus
authored andcommitted
docs: flesh out security policy
1 parent 949ae14 commit fe48769

File tree

1 file changed

+7
-2
lines changed

1 file changed

+7
-2
lines changed

SECURITY.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,11 @@
88

99
## Reporting a Vulnerability
1010

11-
You can report a vulnerability, via Github or mail to [email protected]
11+
If you have discovered a security vulnerability in this project, please report it privately. **Do not disclose it as a public issue.**
12+
This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.
1213

13-
You will receive a feedback typical within 72h.
14+
You can report a vulnerability
15+
- via our [security advisory](https://github.com/Dexus/pem/security/advisories/new) following [GitHub's private vulnerability reporting feature](https://docs.github.com/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability)
16+
17+
18+
You will receive feedback typically within 72h.

0 commit comments

Comments
 (0)