Skip to content

Commit 51bb09f

Browse files
committed
docs: Add vulnerability reporting details.
1 parent e853404 commit 51bb09f

1 file changed

Lines changed: 9 additions & 4 deletions

File tree

CONTRIBUTING.md

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -56,10 +56,11 @@ package scripts to manage the project, E.g. `yarn run test` or
5656
Responsible Disclosure of Security Vulnerabilities
5757
==================================================
5858

59-
Please do not file reports on Github for security issues.
60-
Please review the guidelines on at (link to more info).
61-
Reports should be encrypted using PGP (link to PGP key) and sent to
62-
security@linkedin.com preferably with the title "Github linkedin/css-blocks - <short summary>".
59+
**Do not file an issue on Github for security issues.** Please review
60+
the [guidelines for disclosure][disclosure_guidelines]. Reports should
61+
be encrypted using PGP ([public key][pubkey]) and sent to
62+
[security@linkedin.com][disclosure_email] preferably with the title
63+
"Vulnerability in Github LinkedIn/css-blocks - &lt;short summary&gt;".
6364

6465
Tips for Getting Your Pull Request Accepted
6566
===========================================
@@ -69,3 +70,7 @@ Tips for Getting Your Pull Request Accepted
6970
3. Open an issue first and seek advice for your change before submitting
7071
a pull request. Large features which have never been discussed are
7172
unlikely to be accepted. **You have been warned.**
73+
74+
disclosure_guidelines: https://www.linkedin.com/help/linkedin/answer/62924
75+
pubkey: https://gist.github.com/chriseppstein/3f45d3a8e6fb42f24cb7b3f77f21381e
76+
disclosure_email: mailto:security@linkedin.com?subject=Vulnerability%20in%20Github%20LinkedIn/css-blocks%20-%20%3Csummary%3E

0 commit comments

Comments
 (0)