Skip to content

Commit ee840d4

Browse files
authored
Add some minimal guideline about GHSA (#347)
Fixes #345.
1 parent a7b90ac commit ee840d4

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

CONTRIBUTING.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,9 @@ Feel free to do either or both of these as you see fit (we recommend you do both
1919

2020
4. [Yank] the affected versions of the crate.
2121
5. Request a CVE for your vulnerability: https://iwantacve.org/
22+
Alternatively, you can create a GitHub Security Advisory (GHSA) and let them request
23+
a CVE for you. In this case, you can add the GHSA ID to the RustSec advisory via the
24+
`aliases` field.
2225

2326
## Criteria
2427

0 commit comments

Comments
 (0)