Skip to content

Commit b399880

Browse files
authored
Link to Github advisory database from pub.dev/security (#7372)
1 parent cf96fdd commit b399880

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

doc/security.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,3 +10,12 @@ In the rare event that you find a vulnerability in pub.dev, contact us at
1010

1111
For more information about how Google handles security issues, see
1212
[Google’s security philosophy](https://www.google.com/about/appsecurity/).
13+
14+
## Security advisories for packages
15+
16+
In case of a vulnerability regarding a specific package, use GitHub’s [security
17+
advisory](https://docs.github.com/en/code-security/repository-security-advisories/creating-a-repository-security-advisory)
18+
feature to create a new security advisory. GitHub will review and ingest the
19+
advisory into the central [GitHub Advisory
20+
database](https://github.com/advisories) where you can also go search for
21+
vulnarabilities in Pub ecosystem.

0 commit comments

Comments
 (0)