Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a warning for how to report security vulnerability #36562

Merged
merged 1 commit into from
Oct 24, 2023

Conversation

gsmet
Copy link
Member

@gsmet gsmet commented Oct 18, 2023

It looks like this:

2023-10-18 18 13 09 github com b39fd114b5b8

I will let you bikeshed on the content, adding some Markdown content on top is the best we can do for now.

@gsmet gsmet requested a review from gastaldi October 18, 2023 16:18
@quarkus-bot quarkus-bot bot added the area/infra-automation anything related to CI, bots, etc. that are used to automated our infrastructure label Oct 18, 2023
@abstractj
Copy link
Contributor

abstractj commented Oct 18, 2023

@gsmet for future reference. What would be the process for public known CVEs?

@gsmet
Copy link
Member Author

gsmet commented Oct 20, 2023

@abstractj typically, if you want to ask for us to update a library because of CVE-XXX, you can do it publicly. I will make it clear that it's for vulnerability in Quarkus itself.

@gsmet
Copy link
Member Author

gsmet commented Oct 24, 2023

OK, I followed @gastaldi 's advice. Let's merge as I really prefer it in now. We can tweak it afterwards if need be.

@gsmet gsmet merged commit ec2f3d4 into quarkusio:main Oct 24, 2023
3 checks passed
@quarkus-bot quarkus-bot bot added this to the 3.6 - main milestone Oct 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/infra-automation anything related to CI, bots, etc. that are used to automated our infrastructure
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants