Skip to content

Commit 40f0556

Browse files
authored
Create SECURITY.md
Adapted from neqo. What should the Bugzilla component for this be?
1 parent 0b9edb5 commit 40f0556

1 file changed

Lines changed: 14 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Security Policy
2+
3+
This document describes how security vulnerabilities in this project should be reported.
4+
5+
## Reporting a Vulnerability
6+
7+
To report a security problem with neqo, create a bug in Mozilla's Bugzilla instance in the [Core :: Networking](https://bugzilla.mozilla.org/enter_bug.cgi?product=Core&component=Networking) component.
8+
9+
**IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem".**
10+
We advise that you check this option for anything that involves anything security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.
11+
12+
Review Mozilla's [guides on bug reporting](https://bugzilla.mozilla.org/page.cgi?id=bug-writing.html) before you open a bug.
13+
14+
Mozilla operates a [bug bounty program](https://www.mozilla.org/en-US/security/bug-bounty/), for which this project is eligible.

0 commit comments

Comments
 (0)