Skip to content

Commit 770a249

Browse files
committed
docs: add Orange CERT contact in SECURITY.md
Signed-off-by: Pierre-Yves Lapersonne <pierreyves.lapersonne@orange.com>
1 parent 316f6f6 commit 770a249

File tree

1 file changed

+6
-3
lines changed

1 file changed

+6
-3
lines changed

.github/SECURITY.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,13 @@
11
# Security Policy
22

3-
# Reporting Security Issues
3+
## Reporting Security Issues
44

55
We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
6-
Send an e-mail to [opensource.contact@orange.com](mailto:opensource.contact@orange.com) to report a vulnerability and contact all people in CONTRIBUTORS and MAINTAINERS including the word "SECURITY" in the subject line.
6+
To report a vulnerability, send an e-mail to **both**:
7+
- [opensource.contact@orange.com](mailto:opensource.contact@orange.com)
8+
- and [cert.cc@orange.com](mailto:cert.cc@orange.com)
9+
- and all people in MAINTAINERS including the word "SECURITY" in the subject line
710

811
Please allow our team sufficient time to resolve the vulnerability before disclosing it ; we'll remain in contact about the fix and may ask for your assistance to verify it is resolved.
912

10-
We will endeavor to respond quickly, and will keep you updated throughout the process.
13+
We will endeavor to respond quickly, and will keep you updated throughout the process.

0 commit comments

Comments
 (0)