Skip to content

Commit b9d80bf

Browse files
sidhpurwala-huzaifazhewenl
authored andcommitted
Enhance the pre-notification policy (vllm-project#23532)
Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
1 parent 981fde7 commit b9d80bf

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

SECURITY.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,4 +42,9 @@ For certain security issues of CRITICAL, HIGH, or MODERATE severity level, we ma
4242

4343
* If you wish to be added to the prenotification group, please send an email copying all the members of the [vulnerability management team](https://docs.vllm.ai/en/latest/contributing/vulnerability_management.html). Each vendor contact will be analyzed on a case-by-case basis.
4444

45+
* Organizations and vendors who either ship or use vLLM, are eligible to join the prenotification group if they meet at least one of the following qualifications
46+
* Substantial internal deployment leveraging the upstream vLLM project.
47+
* Established internal security teams and comprehensive compliance measures.
48+
* Active and consistent contributions to the upstream vLLM project.
49+
4550
* We may withdraw organizations from receiving future prenotifications if they release fixes or any other information about issues before they are public. Group membership may also change based on policy refinements for who may be included.

0 commit comments

Comments
 (0)