ppkarwasz opened a new pull request, #44:
URL: https://github.com/apache/logging-site/pull/44

   The "Reporting vulnerabilities" section only pointed reporters to the 
private security mailing list. It now summarizes the reporting guidelines of 
the ASF Security Team and links to them:
   
   - prefix the subject line with `[SECURITY]`,
   - report one finding per e-mail,
   - write the report in plain text,
   - and avoid attachments whose content fits in the body of the e-mail.
    
   Most importantly it reiterates the disclosure terms [set by the ASF Security 
Team](https://security.apache.org/report-code/): the information may be made 
public after triage (for invalid reports) or after the release of a fix.
   
   The identity of the reporter is not disclosed for invalid reports, as it 
serves no purpose and most reporters would not want that.
   
   The "Vulnerability handling" section gets a minor wording cleanup.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to