4 Commits

Author SHA1 Message Date
Jonathan Schwender
30372328c0 Reword our security policy (#42953)
In ac24cd6139 we started asking for people
to use **private** github security reports, but kept the wording from
before, which was related to accepting such reports as **public**
issues.
The wording doesn't make sense in the context of asking people for
private reports, so update the wording to reflect that.
This is not a policy change, just making the wording more clear.

Testing: Not required, policy description.

Signed-off-by: Jonathan Schwender <schwenderjonathan@gmail.com>
2026-03-02 13:37:59 +00:00
zefr0x
2eab9c6df1 docs(security): avoid possible misconception in the security policy (#37032)
With ac24cd6139, the URL is changed from
pointing to the normal Github issues to Github's private security
reporting feature, but the text hasn't been updated to reflect this.


Testing: Static docs file without dynamic effects.

Signed-off-by: zefr0x <zer0-x.7ty50@aleeas.com>
2025-05-16 21:27:42 +00:00
Manuel Rego Casasnovas
ac24cd6139 Update new issue URL in SECURITY.md (#31698)
* Update new issue URL in SECURITY.md

Update URL for new issue so it uses the security template: https://github.com/servo/servo/issues/new?template=security-report.md

* Link to https://github.com/servo/servo/security/advisories/new instead
2024-03-15 15:03:49 +00:00
Manuel Rego Casasnovas
31a50feb4a Add CoC and Security Policy (#31622)
CoC is the same than we have at <https://servo.org/coc/>.

Security Policy is based on the agreement on the last TSC meeting:
https://github.com/servo/project/blob/main/governance/tsc/tsc-2024-02-26.md#security-policy
2024-03-12 11:24:01 +00:00