Skip to content

Commit

Permalink
Add notes regarding security scanners
Browse files Browse the repository at this point in the history
  • Loading branch information
wata727 authored Oct 30, 2024
1 parent 8bb73bb commit 5b450bf
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,3 +7,6 @@ TFLint always supports only the latest version and does not provide security upd
## Reporting a Vulnerability

If you find a vulnerability, please do not report it in an issue or a discussion. You can discuss vulnerabilities internally with maintainers using [private vulnerability reporting](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability).

Please do not just report the results of a security scanner such as Trivy. In many cases, maintainers are already aware of the existence of vulnerable libraries via Dependabot alerts.
We welcome reports of exploits and their impact that you have analyzed based on the output of security scanners.

0 comments on commit 5b450bf

Please sign in to comment.