<#17713 Formalize our security and vulnerability r...
# github-notifications
q
#17713 Formalize our security and vulnerability reporting policy Issue created by Eric-Arellano The Linux Foundation recommends having a SECURITY.md file documenting our reporting policy. We want to make it as easy as possible for people to report vulnerabilities to us. Over Slack, the maintainers are tentatively thinking that it's sufficient to have reporters email the maintainer group. No need for a new dedicated Google Group. That ensures that multiple eyes are on it. The Linux Foundation recommends committing to an embargo time period. After n weeks, the reporter is free to publicize and shame us for not fixing it. That pressure/fire encourages reporters that we will take the report seriously, and it keeps us accountable. The Foundation recommends a shorter embargo period if possible, like 2-3 weeks. Many policies have a clause that allows negotiating the time frame with the reporter if we believe we need more time to fix it. We should look at the language from other open source projects. pantsbuild/pants