Skip to content

Commit 8fd41b5

Browse files
geeknoidlinsun
authored andcommitted
Update early disclosure doc, per steering committee. (kubernetes#178)
1 parent c4190dc commit 8fd41b5

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

EARLY-DISCLOSURE.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,12 @@ The list is used to provide actionable information to close Istio partners.
1010
The list is *NOT* intended for individuals to find out about
1111
security issues.
1212

13+
Istio has upstream dependencies of its own. In certain situations, we may need to make emergency
14+
Istio releases to address vulnerabilities in these upstream dependencies. Due to embargo policies of
15+
these dependencies, we may not be allowed to share any details about the vulnerabilities. In that
16+
case, Istio's early disclosure will be strictly focused on the mechanics of an upcoming patch
17+
release, rather than on the details of the discovered vulnerabilities.
18+
1319
## Embargo policy
1420

1521
The information members receive from the mailing list must not be
@@ -36,9 +42,7 @@ will be removed from the early disclosure list.
3642

3743
| Email | Organization |
3844
| ------------- |:-------------:|
39-
| | |
40-
41-
TBD: List email addresses used to report early disclosure
45+
| [email protected] | Aspen Mesh |
4246

4347
### Membership criteria
4448

0 commit comments

Comments
 (0)