-
Notifications
You must be signed in to change notification settings - Fork 100
Closed
Labels
maintenanceDependency changes, security updates, infrastructure tweaks & general mainenanceDependency changes, security updates, infrastructure tweaks & general mainenance
Milestone
Description
Hi,
Today I saw a security issue reported in the mailing list for Skosmos. I think an alternative workflow would be to have an email listed in a file where users could redirect this kind of request. Then devs could confirm the issue and work on a new release with the security fix.
It's common to have a SECURITY.md file detailing which channels to use to report security issues, what the process is like, etc. Maybe we should adopt one too?
Bruno
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
maintenanceDependency changes, security updates, infrastructure tweaks & general mainenanceDependency changes, security updates, infrastructure tweaks & general mainenance