Skip to content

Commit 888154f

Browse files
authored
docs: better expectation management for vulnerabilities (#1016)
1 parent fe8adc6 commit 888154f

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

SECURITY.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,12 @@
22

33
## Reporting a Vulnerability
44

5-
Please do not open an issue if you find a vulnerability. Send an email to [email protected] and a maintainer will get in touch with you as soon as possible. This might take up to 72 hours.
5+
Please _do not_ open an issue if you find a vulnerability. Send an email to [email protected] and a maintainer will get in touch with you.
6+
Please note that this project is maintained by volunteers and therefore, an answer might take some time.
67

7-
You will be kept up to date with all developments via email.
8+
Please provide at least the following information in your report:
89

9-
Once your report has been checked and the vulnerability is confirmed, it will be patched as soon as possible and issue a security advisory will be released with the patch.
10+
- A description of the vulnerability and its impact
11+
- How to reproduce the issue
12+
13+
This project is maintained by a team of volunteers on a reasonable-effort basis. As such, please give us at least 90 days to work on a fix before public exposure.

0 commit comments

Comments
 (0)