Skip to content

Commit 2d5374d

Browse files
authored
docs: add security escalation policy (#40391)
1 parent 5e64c57 commit 2d5374d

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

SECURITY.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,3 +11,9 @@ If you have discovered a security vulnerability in this project, please report i
1111
Please disclose it at [security advisory](https://github.com/ampproject/amphtml/security/advisories/new).
1212

1313
This project is maintained by a team on a best effort basis. As such, vulnerability reports will be investigated and fixed or disclosed as soon as possible.
14+
15+
## Escalation
16+
17+
If you do not receive an acknowledgement of your report within 6 business days, or if you cannot find a private security contact for the project, you may escalate to the OpenJS Foundation CNA at `[email protected]`.
18+
19+
If the project acknowledges your report but does not provide any further response or engagement within 14 days, escalation is also appropriate.

0 commit comments

Comments
 (0)