Skip to content

Commit 4588d1d

Browse files
Clarify security policy credit and reported-by note (#1980)
* Clarify security policy credit and reported-by note Signed-off-by: Stephen Mackenzie <[email protected]> * Update SECURITY.md Signed-off-by: Jean-Christophe Morin <[email protected]> --------- Signed-off-by: Stephen Mackenzie <[email protected]> Signed-off-by: Jean-Christophe Morin <[email protected]> Co-authored-by: Jean-Christophe Morin <[email protected]>
1 parent c4757b0 commit 4588d1d

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

SECURITY.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,16 +9,18 @@ If you think you've found a potential vulnerability in rez, please
99
report it by filing a GitHub [security
1010
advisory](https://github.com/AcademySoftwareFoundation/rez/security/advisories/new). Alternatively,
1111
email [email protected] and provide your contact info for further
12-
private/secure discussion. If your email does not receive a prompt
13-
acknowledgement, your address may be blocked.
12+
private/secure discussion. If your email does not receive a prompt
13+
acknowledgement, your address may be blocked. If you request anonymity,
14+
your name and contact information will not be published. Otherwise,
15+
credit will be given in notices related to the vulnerability.
1416

1517
Our policy is to acknowledge the receipt of vulnerability reports
1618
within 48 hours. Our policy is to address critical security vulnerabilities
1719
rapidly and post patches within 14 days if possible.
1820

1921
## Known Vulnerabilities
2022

21-
The only currently known security vulnerability is issue [#937](https://github.com/AcademySoftwareFoundation/rez/issues/937).
23+
The only currently known security vulnerability is issue [#417](https://github.com/AcademySoftwareFoundation/rez/issues/417), reported by @ttanimura.
2224
No others are known at this time.
2325

2426
See the [release notes](CHANGES.md) for more information.

0 commit comments

Comments
 (0)