We don't need to be the dispatch for all vulns, now that other projects are starting to have their own processes. But we don't want to discourage reports about stuff that isn't directly in k/k either. Saying that we usually disclose vuln reports in 7 days is just not true. But, I think it's still good to aim for 7 days when we aren't blocked on and coordinating release of patches. |
||
---|---|---|
.. | ||
_common-resources | ||
blog | ||
case-studies | ||
community | ||
docs | ||
examples | ||
includes | ||
partners | ||
OWNERS | ||
_index.html |