Skip to content

Commit 03eede1

Browse files
UlisesGascondhmlau
authored andcommitted
docs: add security escalation policy
Signed-off-by: Ulises Gascón <[email protected]>
1 parent ed7a49d commit 03eede1

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

SECURITY.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,3 +71,12 @@ If you think you have discovered a new security issue with any LoopBack package,
7171

7272
If you are sending us any logs as part of the report, then make sure to redact
7373
any sensitive data from them.
74+
75+
## Escalation
76+
77+
If you do not receive an acknowledgement of your report within 6 business days,
78+
or if you cannot find a private security contact for the project, you may
79+
escalate to the OpenJS Foundation CNA at `[email protected]`.
80+
81+
If the project acknowledges your report but does not provide any further
82+
response or engagement within 14 days, escalation is also appropriate.

0 commit comments

Comments
 (0)