Skip to content

Commit e04de30

Browse files
authored
docs: update "Disclosure Timeline and Public Announcement" section (#20)
1 parent 558d4a0 commit e04de30

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

SECURITY.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -27,14 +27,15 @@ We also support [Coordinated Vulnerability Disclosure (CVD)](https://en.wikipedi
2727

2828
### Important Reminder
2929

30-
**Do not create a public issue to report a security vulnerability.** This is to protect both the project and its users from potential exploitation before the issue is resolved.
30+
🚨**Do not create a public issue to report a security vulnerability.** This is to protect both the project and its users from potential exploitation before the issue is resolved.
3131

3232
### Disclosure Timeline and Public Announcement
3333

34-
- We aim to acknowledge receipt of your report within **2–5 working days**.
35-
- We will keep you informed of our progress as we investigate and work on fixes.
36-
- In general, we strive to fix or otherwise address confirmed vulnerabilities within **30 days**, though timelines may vary depending on severity and complexity. We will coordinate with you regarding public disclosure once a fix is available or mitigation is in place.
37-
- Please **do not publicly disclose** details of the vulnerability until we have confirmed a fix or provided approval, to ensure the security of our users.
34+
- **Acknowledgment**: We will acknowledge receipt of your report within **2–5 working days**.
35+
- **Progress Updates**: We will keep you informed as we investigate and work on a fix.
36+
- **Resolution Time**: We aim to resolve confirmed vulnerabilities within **30 days**, but complex issues may take longer.
37+
- **Public Disclosure**: We coordinate with you on public disclosure only after a fix or mitigation is in place.
38+
- **Researcher Recognition**: With your permission, we acknowledge security researchers in the public advisory after the fix.
3839

3940
### Acknowledgements
4041

0 commit comments

Comments
 (0)