Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Sec Policy: Add community maintained language
Signed-off-by: Josh Richards <[email protected]>
  • Loading branch information
joshtrichards authored Oct 24, 2023
commit 45bcaef051b6de7d6957d25a2308971f6a1604d3
6 changes: 5 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,11 @@ Your report should include:
You should receive an initial acknowledgement within 24 hours in most cases.

A member of the security team will confirm the vulnerability, determine its impact, follow-up with any questions,
and coordinate the fix and publication.
and coordinate the fix and publication.

If the vulnerability involves an app that is not formally maintained by Nextcloud (i.e. hosted by the
Nextcloud project but community maintained), the security team will contact the current maintainer
and help make sure the issue gets fixed.

The fix will be applied to all applicable and still supported stable branches, tested, and packaged in the next security release.
The vulnerability will be publicly announced after the release. Finally, your name will be added
Expand Down