Skip to content

Commit

Permalink
update VD policy per feedback from September 2023 TC39 plenary
Browse files Browse the repository at this point in the history
  • Loading branch information
ctcpip authored Nov 9, 2023
1 parent 9819405 commit 56cb8cc
Showing 1 changed file with 6 additions and 6 deletions.
12 changes: 6 additions & 6 deletions docs/draft-SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,22 +2,22 @@

## Reporting Guidelines

- If the vulnerability is present in an implementation, then [report it directly](#reporting-a-vulnerability-to-projects) to the relevant project using their vulnerability reporting process.
- If the vulnerability is present in a TC39 specification, [let us know](#reporting-a-vulnerability-to-tc39).
- If a security issue is present in an implementation, then [report it directly](#reporting-to-projects) to the relevant project.
- If a security issue is present in a TC39 specification, [let us know](#reporting-to-tc39).
- Include any relevant links to corroborative information, e.g. vulnerability reports, reference IDs, etc.
- If you are unable to determine whether the vulnerability is implementation-specific, [let us know](#reporting-a-vulnerability-to-tc39).
- If you are unable to determine whether a security issue is implementation-specific, [let us know](#reporting-to-tc39).

## Reporting a Vulnerability to TC39
## Reporting to TC39

- GitHub private vulnerability reporting (add link when available)
- Send an email to `security@tc39.es`

## Reporting a Vulnerability to Projects
## Reporting to Projects

> [!NOTE]
> This list is not exhaustive.
| Engine/Platform | Used In | Report a Vulnerability |
| Engine/Platform | Used In | Link to Report |
| --------------- | ---------------------- | ----------------------------------------------- |
| JavaScriptCore | Safari | [Report](https://webkit.org/security-policy/) |
| Node | | [Report](https://nodejs.dev/en/about/security/) |
Expand Down

0 comments on commit 56cb8cc

Please sign in to comment.