Skip to content

Commit 91836e9

Browse files
committed
Update instructions for vulnerability reporting
This has been discussed in the TSC before. Signed-off-by: Till Schneidereit <till@tillschneidereit.net>
1 parent b5ccf0f commit 91836e9

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

security.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,11 @@ title: Security Policy
1010

1111
## Reporting a security bug in a Bytecode Alliance project
1212

13-
If you think you have found a security issue in a Bytecode Alliance project,
14-
please send email to <security@bytecodealliance.org>.
13+
Security is a top priority for the Bytecode Alliance. As such, we take all reports of suspected security vulnerabilities seriously, and have a number of ways to report them.
14+
15+
For suspected vulnerabilities in a specific project, prefer to report the issue using GitHub's [private vulnerability reporting](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) facilities. Maintainers will then work with you to resolve the issue.
16+
17+
If you think that that channel isn't right for reporting your specific issue, you can also send email to <security@bytecodealliance.org>.
1518
This list is delivered to a small security team. We will then acknowledge receipt
1619
of your report and prioritize initial analysis of severity.
1720

0 commit comments

Comments
 (0)