-
-
Notifications
You must be signed in to change notification settings - Fork 406
Open
Description
fdk-aac lacks a SECURITY.md
If a vulnerability is found in fdk-aac, a researcher will not know how to privately raise the issue with your developers. The only places I could find to report is on this public issue tracker or on public mailing lists.
By defining a Security Policy, fdk-aac can set clear expectations to reporters who want to keep fdk-aac and users safe.
Here's GitHub Security's policy as an example. Another option is to use GitHub's private vulnerability reporting feature.
Metadata
Metadata
Assignees
Labels
No labels