Commit Graph

4 Commits

Author SHA1 Message Date
ctz 6e9a61f055 SECURITY.md: use github vuln reporting tool
We have a mailing list for this. But, the first time that was used for real, it didn't go very well:

- the report and a follow-up went into spam. A private google group delivering to gmail -- you'd think this would work well, but  it did not.
- there was only me in the group.

Github now has a "private vulnerability reporting" feature that should be better for getting reports to the right people quickly. Let's try that?
2023-08-23 08:11:50 +00:00
Dirkjan Ochtman 0b86e5e6f4 Limit scope of security support based on time 2023-06-30 13:40:06 +01:00
Joseph Birr-Pixton 2822f9e795 Adopt the Rust CoC; use mailing list for vuln reports 2021-08-08 11:13:45 +01:00
ctz 881bdcb5f6
Add SECURITY.md
This restates the vuln reporting policy in CONTRIBUTING.md
2020-07-18 18:26:41 +01:00