Skip to content

Commit

Permalink
Update SECURITY.md to reflect the new Github security page and the fo…
Browse files Browse the repository at this point in the history
…cus on user access vs. program access.
  • Loading branch information
michaelrsweet committed Jun 27, 2023
1 parent 1327ad8 commit b0995ef
Showing 1 changed file with 19 additions and 8 deletions.
27 changes: 19 additions & 8 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,25 @@ This file describes how security issues are reported and handled, and what the
expectations are for security issues reported to this project.


Reporting a Security Bug
------------------------

For the purposes of this project, a security bug is a software defect that
allows a *local or remote user* to gain unauthorized access or privileges on the
host computer or to cause the software to crash. Such defects should be
reported to the project security advisory page at
<https://github.com/OpenPrinting/libcups/security/advisories>.

Alternately, security bugs can be reported to "security AT msweet.org" using the
PGP public key below. Expect a response within 5 business days. Any proposed
embargo date should be at least 30 days and no more than 90 days in the future.

> *Note:* If you've found a software defect that allows a *program* to gain
> unauthorized access or privileges on the host computer or causes the program
> to crash, that defect should be reported as an ordinary project issue at
> <https://github.com/OpenPrinting/libcups/issues>.

Responsible Disclosure
----------------------

Expand Down Expand Up @@ -50,14 +69,6 @@ example:
1.0rc1


Reporting a Vulnerability
-------------------------

Report all security issues to "security AT msweet.org". Expect a response
within 5 business days. Any proposed embargo date should be at least 30 days
and no more than 90 days in the future.


PGP Public Key
--------------

Expand Down

0 comments on commit b0995ef

Please sign in to comment.