You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .github/SECURITY.md
+18-5Lines changed: 18 additions & 5 deletions
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,24 @@
1
1
# Reporting Security Issues
2
2
3
-
The JSON Schema project does not house any implementation of JSON Schema itself. If you have found a security issue in any implementation of JSON Schema, please contact the appropriate maintainers, per the projects security reporting guidelines, if any.
3
+
The JSON Schema project does not house any implementation of JSON Schema itself.
4
+
If you have found a security issue in any implementation of JSON Schema, please
5
+
contact the appropriate maintainers, per the projects security reporting
6
+
guidelines, if any.
4
7
5
-
To report a security issue, please use the GitHub Security Advisory "https://github.com/json-schema-org/json-schema-spec/security/advisories/new" tab.
8
+
To report a security issue, please use the GitHub Security Advisory
If you find a security issue in relation to the JSON Schema specification or another repository within this GitHub organization, please use the above.
12
+
If you find a security issue in relation to the JSON Schema specification or
13
+
another repository within this GitHub organization, please use the above.
8
14
9
-
The JSON Schema project TSC will review and respond to all security reports. Please follow [coordinated disclosure](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/about-coordinated-disclosure-of-security-vulnerabilities).
15
+
The JSON Schema project TSC will review and respond to all security reports.
If you need assistance in understanding a report, or remediation of a confirmed
21
+
issue, please feel free to reach out to us on our Slack server, in the
22
+
`#implementations` channel, and ask for a temporary private channel to discuss
23
+
your situation or concerns.
10
24
11
-
If you are a maintainer of an implementation, please consider [adding a security policy](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository). If you need assistance in understanding a report, or remediation of a confirmed issue, please feel free to reach out to us on our Slack server, in the `#implementations` channel, and ask for a temporary private channel to discuss your situation or concerns.
0 commit comments