Skip to content

Commit 3955090

Browse files
committed
Add note on disclosure policy
1 parent 14a340f commit 3955090

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

src/pages/security.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,12 @@ The maintainers reserve the right to make a pragmatic decision to make adjustmen
2020
Instead, **report the vulnerability privately** via the Security tab on the [graphql-java GitHub repository](https://github.com/graphql-java/graphql-java). See instructions at [https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability).
2121
:::
2222

23+
## Disclosure policy
24+
The GraphQL Java maintainers will collaborate with those who report vulnerabilities privately via the [GitHub vulnerability reporting form](https://www.graphql-java.com/security).
25+
We will acknowledge and review vulnerability reports as soon as we can. To protect the community, please do not publicly disclose the vulnerability.
26+
The maintainers will make a public announcement after the vulnerability is fixed.
27+
28+
Please allow time for the maintainers to review vulnerability reports, please note we are an open source project run by volunteers.
2329

2430
## Common Vulnerabilities and Exposures (CVEs)
2531

0 commit comments

Comments
 (0)