docs: point security reports at private disclosure
This commit is contained in:
parent
206ee9a155
commit
fac2f540c5
1 changed files with 13 additions and 2 deletions
|
|
@ -7,5 +7,16 @@ https://github.com/deskflow/deskflow/releases
|
|||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
Please report vulnerabilities on our issue tracker as bugs:
|
||||
https://github.com/deskflow/deskflow/issues
|
||||
Please report vulnerabilities privately, not on the public issue tracker.
|
||||
|
||||
Use GitHub's private reporting form:
|
||||
https://github.com/deskflow/deskflow/security/advisories/new
|
||||
|
||||
That opens a draft advisory only visible to maintainers. Include a proof of concept
|
||||
if you have one.
|
||||
|
||||
## What happens next
|
||||
|
||||
We land the fix on master, ship it in a continuous build, then publish the advisory
|
||||
and proof of concept together, so a fixed build is always available at the point the
|
||||
details go public. You will be credited in the advisory unless you ask otherwise.
|
||||
|
|
|
|||
Loading…
Reference in a new issue