Skip to content

Commit 977cfef

Browse files
committed
Add FAQ on reporting vulnerabilities
Signed-off-by: Ivan Kanakarakis <ivan.kanak@gmail.com>
1 parent cca6011 commit 977cfef

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

security.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,12 @@ GitHub’s guidance on managing these types of vulnerabilities.
1414

1515
## FAQ
1616

17+
- How can I report a security vulnerability?
18+
19+
Anyone can submit a potential security vulnerability to
20+
`incident-response@idpy.org`. The incident-response team will verify the
21+
issue and contact you on how this will be handled.
22+
1723
- Are CVEs created for each security vulnerability?
1824

1925
Yes. Each vulnerability that is reported and verified is assigned a CVE
@@ -66,7 +72,7 @@ GitHub’s guidance on managing these types of vulnerabilities.
6672
Upgrade to the latest version. At this point, IdentityPython does not have
6773
the resources required to provide backports of security issues or other
6874
fixes. We urge the community to try to keep up with the latest version. The
69-
organization advocates FOSS and is open to new colaborators. Since,
75+
organization advocates FOSS and is open to new collaborators. Since,
7076
everything is open, users are free to backport patches on their own.
7177

7278

0 commit comments

Comments
 (0)