Skip to content

Commit

Permalink
Add security template
Browse files Browse the repository at this point in the history
  • Loading branch information
atoomic committed Oct 20, 2019
1 parent 913b4d0 commit 514b901
Show file tree
Hide file tree
Showing 2 changed files with 14 additions and 0 deletions.
1 change: 1 addition & 0 deletions MANIFEST
Original file line number Diff line number Diff line change
Expand Up @@ -5355,6 +5355,7 @@ README.tw Perl for Traditional Chinese (in Big5)
README.vms Notes about installing the VMS port
README.vos Perl notes for Stratus VOS
README.win32 Perl notes for Windows
SECURITY.md Add Security Policy for GitHub
reentr.c Reentrant interfaces
reentr.h Reentrant interfaces
regcharclass.h Generated by regen/regcharclass.pl
Expand Down
13 changes: 13 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Security Policy

## Reporting a Vulnerability

If you believe you have found a security vulnerability in Perl, please email the details to [email protected]

This creates a new Request Tracker ticket in a special queue which isn't initially publicly accessible. The email will also be copied to a closed subscription unarchived mailing list which includes all the core committers, who will be able to help assess the impact of issues, figure out a resolution, and help co-ordinate the release of patches to mitigate or fix the problem across all platforms on which Perl is supported. Please only use this address for security issues in the Perl core, not for modules independently distributed on CPAN.

When sending an initial request to the security email address, please don't Cc any other parties, because if they reply to all, the reply will generate yet another new ticket. Once you have received an initial reply with a [perl #NNNNNN] ticket number in the headline, it's okay to Cc subsequent replies to third parties: all emails to the perl5-security-report address with the ticket number in the subject line will be added to the ticket; without it, a new ticket will be created.

## PerlSec

Read more at https://perldoc.perl.org/perlsec.html

0 comments on commit 514b901

Please sign in to comment.