File tree 1 file changed +3
-3
lines changed
1 file changed +3
-3
lines changed Original file line number Diff line number Diff line change 4
4
5
5
Please focus your analysis on the [ latest] ( https://github.com/Xanthic/cache-api/releases/latest ) version of the library.
6
6
7
- If the project maintainers deem the issue to be particularly significant, a patch may be backported to some previous verisons .
7
+ If the project maintainers deem the issue to be particularly significant, a patch may be backported to some previous versions .
8
8
9
9
10
10
## Reporting a Vulnerability
11
11
12
- Please privately report any vulnerabilites as a [ Github Security Advisory] ( https://github.com/Xanthic/cache-api/security/advisories/new ) .
12
+ Please privately report any vulnerabilities as a [ Github Security Advisory] ( https://github.com/Xanthic/cache-api/security/advisories/new ) .
13
13
14
14
We will acknowledge the report within a week and begin investigating.
15
15
@@ -19,7 +19,7 @@ Our vulnerability disclosure guidelines are similar to Google's [Project Zero ru
19
19
20
20
Once you report a vulnerability, we have 90 days to make a patch available for users.
21
21
Once a patch is released, you may publicly disclose the vulnerability details after 30 more days (so users have time to upgrade).
22
- If we do not release a patch in this period, you can publicly disclose the details of the vulnerability without further delay.
22
+ If we do not release a patch within this period, you can publicly disclose the details of the vulnerability without further delay.
23
23
24
24
If the vulnerability is shown to be already exploited "in the wild," the 90-day period is replaced by a 10-day period.
25
25
However, the 30 additional days before public disclosure still apply, if we are able to publish a patch within the period.
You can’t perform that action at this time.
0 commit comments