Reword our security policy (#42953)

In ac24cd6139 we started asking for people
to use **private** github security reports, but kept the wording from
before, which was related to accepting such reports as **public**
issues.
The wording doesn't make sense in the context of asking people for
private reports, so update the wording to reflect that.
This is not a policy change, just making the wording more clear.

Testing: Not required, policy description.

Signed-off-by: Jonathan Schwender <schwenderjonathan@gmail.com>
This commit is contained in:
Jonathan Schwender
2026-03-02 14:37:59 +01:00
committed by GitHub
parent e033588b30
commit 30372328c0

View File

@@ -1,4 +1,3 @@
# Security Policy
Given that Servo does not yet have customers or products, we are comfortable accepting the security related issues as [GitHub security reports](https://github.com/servo/servo/security/advisories/new) for now.
Please submit security related issues as [GitHub security reports](https://github.com/servo/servo/security/advisories/new).