Skip to content

Commit

Permalink
Restore original opening paragraph
Browse files Browse the repository at this point in the history
  • Loading branch information
JLLeitschuh authored Nov 7, 2024
1 parent 5c75ec5 commit 5dbc998
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/Outbound_Vulnerability_Disclosure_Policy_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ Open an issue under the [OpenSSF Vulnerability Disclosure Working Group Reposito

## Manual Disclosure Policy

We believe that vulnerability disclosure is a collaborative, two-way street. All parties, maintainers[^1], as well as researchers, must act responsibly. This is why we adhere to a maximum 90-day public disclosure time limit, the “Time Limit”. We immediately privately report to maintainers when we discover vulnerabilities within their software, the “Notice Date”. If a project responds to the private report within 21 calendar days, the details will be publicly disclosed (shared with the defensive community) after 90 days, the “Publication Date”, or sooner if the maintainer releases a fix prior to the Publication Date. That Publication Date can vary in the following ways:
We believe that vulnerability disclosure is a collaborative, two-way street. All parties involved, including but not limited to maintainers[^1], as well as researchers, must act responsibly. This is why we adhere to a maximum 90-day public disclosure time limit, the “Time Limit”. We immediately privately report to maintainers when we discover vulnerabilities within their software, the “Notice Date”. If a project responds to the private report within 21 calendar days, the details will be publicly disclosed (shared with the defensive community) 90 days after the Notice Date, on the “Publication Date”, or sooner if the maintainer releases a fix prior to the Publication Date. That Publication Date can vary in the following ways:

- If a Time Limit is due to expire on a weekend or major public holiday, the Publication Date will be moved to the next normal work day. We are a global community and if there is a conflict, we kindly request that maintainers communicate these conflicts up-front.
- We expect maintainers to respond within 21 calendar days of the Notice Date to let us know how the issue is being mitigated to protect impacted end-users. If we do not receive any engagement from the maintainers within 35 days of the Notice Date, that affirms their intention to fix the vulnerability within the Time Limit, we reserve the right to fully publicly disclose the vulnerability at that point.
Expand Down

0 comments on commit 5dbc998

Please sign in to comment.