From 9a6f7d4361296c8fcec58135fc14be26600abd27 Mon Sep 17 00:00:00 2001 From: "Sahdev P. Zala" Date: Thu, 16 May 2019 10:32:32 -0400 Subject: [PATCH] README: update handling of security vulnerabilities We may not want to suggest to contact CoreOS now. We could remove this section but consiering the nature of the subject, discussion with the project maintainers probably a good idea if someone doesn't find it comfortable to report an issue right away. --- README.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/README.md b/README.md index d1cd2fc62e2..7ca545b10b2 100644 --- a/README.md +++ b/README.md @@ -171,9 +171,7 @@ See [reporting bugs](Documentation/reporting_bugs.md) for details about reportin ## Reporting a security vulnerability -Due to their public nature, GitHub and mailing lists are NOT appropriate places for reporting vulnerabilities. Please refer to CoreOS's [security disclosure][disclosure] process when reporting issues that may be security related. - -[disclosure]: https://coreos.com/security/disclosure/ +A security vulnerability can be reported as an issue, however, GitHub and mailing lists may NOT always be an appropriate place for reporting vulnerabilities. In that case, please reach out to the project [MAINTAINERS](https://github.com/etcd-io/etcd/blob/master/MAINTAINERS) to first discuss the vulnerabilities with them and take necessary action per such discussion. ### License