Skip to content

Commit 777ffa0

Browse files
authored
Merge pull request #163 from AkihiroSuda/security-disclosure
SECURITY.md: relax disclosure policy
2 parents fd085f4 + 5efb4bc commit 777ffa0

1 file changed

Lines changed: 9 additions & 1 deletion

File tree

SECURITY.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ reach out to any committer directly to confirm receipt of the issue.
2727

2828
Once a committer has confirmed the relevance of the report, a draft security
2929
advisory will be created on Github. The draft advisory will be used to discuss
30-
the issue with committers, the reporter(s), and containerd's security advisors.
30+
the issue with people including committers, the reporter(s), and containerd's security advisors.
3131
If the reporter(s) wishes to participate in this discussion, then provide
3232
reporter Github username(s) to be invited to the discussion. If the reporter(s)
3333
does not wish to participate directly in the discussion, then the reporter(s)
@@ -42,6 +42,14 @@ patch release, and the date of public disclosure. The reporter(s) are expected
4242
to participate in the discussion of the timeline and abide by agreed upon dates
4343
for public disclosure.
4444

45+
Prior to the public disclosure, the vulnerability may be shared with:
46+
- Owners of the `@containerd` organization, including CNCF staff
47+
- Committers
48+
- Security Advisors
49+
- Reporter(s)
50+
- Reporter(s) of identical or very similar vulnerabilities
51+
- Additional contributors or experts who can provide context, at the discretion of the Committers
52+
4553
## Supported Versions
4654

4755
See the [containerd releases page](https://github.com/containerd/containerd/blob/master/RELEASES.md#support-horizon)

0 commit comments

Comments
 (0)