Skip to content

Commit b8c0ed6

Browse files
committed
update security policy
Signed-off-by: Nicklas Körtge <nicklas.koertge1@ibm.com>
1 parent 49dc4aa commit b8c0ed6

File tree

1 file changed

+7
-4
lines changed

1 file changed

+7
-4
lines changed

SECURITY.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,12 @@
11
# Reporting Security Issues
22

3-
We and community take security bugs seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
3+
You can privately report a potential security issue via the GitHub security advisory feature. This can be done here:
44

5-
To report a security issue, email [nicklas.koertge1@ibm.com](mailto:nicklas.koertge1@ibm.com) and include the word "SECURITY" in the subject line.
5+
https://github.com/IBM/sonar-cryptography/security/advisories
66

7-
Wem will send a response indicating the next steps in handling your report. After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
7+
Please do **not** open a public issue about a potential security vulnerability.
88

9-
Report security bugs in third-party modules to the person or team maintaining the module.
9+
You can find more details on the security vulnerability feature in the GitHub
10+
documentation here:
11+
12+
https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability

0 commit comments

Comments
 (0)