-
Notifications
You must be signed in to change notification settings - Fork 432
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add a security policy #882
Comments
But is it useful? |
Well, we might want to have an advisory for the undefined behavior that was fixed with Rand 0.7.0. |
True. We did backport (#853) so users should be recommended to upgrade to |
I opened rustsec/advisory-db#149. |
@tarcieri perhaps you have an opinion on whether this is useful enough to justify yet-another-piece-of-documentation? The only explicit information it adds is a list of which versions will receive security updates — yet (a) this doesn't rule out backports (e.g. #853) and (b) this doesn't even attempt to answer the question of when a potential security issue is worth addressing (e.g. #699 prompted us to avoid use of |
I think it's useful, particularly documenting the "bar" for a |
We could use GitHub's security tab with the following
SECURITY.md
:The text was updated successfully, but these errors were encountered: