Skip to content

Commit a76c166

Browse files
docs: add security escalation policy
Closes #1810 Co-authored-by: Timo Tijhof <krinkle@fastmail.com>
1 parent a018fdc commit a76c166

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

SECURITY.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,3 +9,9 @@ The [latest release](https://qunitjs.com/#current-release) of QUnit is supported
99
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible.
1010

1111
E-mail your findings to security@jquery.com. Thanks!
12+
13+
## Escalation
14+
15+
If you do not receive an acknowledgement of your report within 6 work days, you may escalate to the OpenJS Foundation CNA at `security@lists.openjsf.org`.
16+
17+
If your report is acknowledged but you receive no further response or engagement within 14 days, escalation is also appropriate.

0 commit comments

Comments
 (0)