Skip to content

Commit

Permalink
docs: update security policy wording
Browse files Browse the repository at this point in the history
Replace "security problem/vulnerability" with "security issue".

Signed-off-by: Radu Weiss <[email protected]>
  • Loading branch information
raduweiss authored and alxiord committed Dec 2, 2019
1 parent a6b6db1 commit c038cc8
Showing 1 changed file with 7 additions and 7 deletions.
14 changes: 7 additions & 7 deletions SECURITY-POLICY.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
# Security Problem Policy
# Security Issue Policy

If you uncover a security problem with Firecracker, please write to us on
If you uncover a security issue with Firecracker, please write to us on
<[email protected]>.

Once the Firecracker [maintainers](MAINTAINERS.md) become aware (or are made
aware) of a security vulnerability, they will immediately assess it. Based on
impact and complexity, they will determine an embargo period (if externally
reported, the period will be agreed upon with the external party).
aware) of a security issue, they will immediately assess it. Based on impact and
complexity, they will determine an embargo period (if externally reported, the
period will be agreed upon with the external party).

During the embargo period, maintainers will prioritize developing a fix over
other activities. Within this period, maintainers may also notify a limited
Expand All @@ -16,7 +16,7 @@ technical information, a risk assessment, and early access to a fix.
The external customers are included in this group based on the scale of their
Firecracker usage in production. The pre-disclosure list may also contain
significant external security contributors that can join the effort to fix the
vulnerability during the embargo period.
issue during the embargo period.

At the end of the embargo period, maintainers will publicly release information
about the vulnerability together with the Firecracker patches that mitigate it.
about the security issue together with the Firecracker patches that mitigate it.

0 comments on commit c038cc8

Please sign in to comment.