|
1 | 1 | # Security Policies and Procedures |
2 | 2 |
|
3 | | -This document outlines security procedures and general policies for the |
4 | | -Koperator project. |
| 3 | +## Reporting an Issue |
5 | 4 |
|
6 | | -- [Reporting a Bug](#reporting-a-bug) |
7 | | -- [Disclosure Policy](#disclosure-policy) |
8 | | -- [Comments on this Policy](#comments-on-this-policy) |
9 | | - |
10 | | -## Reporting a Bug |
11 | | - |
12 | | -The Koperator team and community take all security bugs in |
13 | | -Koperator seriously. Thank you for improving the security of |
14 | | -Koperator. We appreciate your efforts and responsible disclosure and |
15 | | -will make every effort to acknowledge your contributions. |
16 | | - |
17 | | -Report security bugs by emailing `[email protected]`. |
18 | | - |
19 | | -The lead maintainer will acknowledge your email within 48 hours, and will send a |
20 | | -more detailed response within 48 hours indicating the next steps in handling |
21 | | -your report. After the initial reply to your report, the security team will |
22 | | -endeavor to keep you informed of the progress towards a fix and full |
23 | | -announcement, and may ask for additional information or guidance. |
| 5 | +If you need to report a security issue please visit [Notifying Adobe of Security Issues](https://helpx.adobe.com/ca/security/alertus.html) |
24 | 6 |
|
25 | 7 | ## Disclosure Policy |
26 | 8 |
|
27 | | -When the security team receives a security bug report, they will assign it to a |
28 | | -primary handler. This person will coordinate the fix and release process, |
29 | | -involving the following steps: |
30 | | - |
31 | | -- Confirm the problem and determine the affected versions. |
32 | | -- Audit code to find any potential similar problems. |
33 | | -- Prepare fixes for all releases still under maintenance. These fixes will be |
34 | | - released as quickly as possible. |
35 | | - |
36 | | -## Comments on this Policy |
37 | | - |
38 | | -If you have suggestions on how this process could be improved please submit a |
39 | | -pull request. |
| 9 | +For more information on our disclosure policy please visit [Vulnerability Disclosure Program Policy](https://helpx.adobe.com/security/policy.html) |
0 commit comments