From 8706890f9b8b5b743616b82e93407fb02a46e7e6 Mon Sep 17 00:00:00 2001 From: Jacob Vosmaer Date: Mon, 28 Oct 2013 15:44:28 +0100 Subject: Refer to disclosure policy in CONTRIBUTING.md --- CONTRIBUTING.md | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'CONTRIBUTING.md') diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 9d9be5bdc21..d1fdd93850a 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -5,6 +5,7 @@ This guide details how to use issues and pull requests to improve GitLab. - [Closing policy for issues and pull requests](#closing-policy-for-issues-and-pull-requests) - [Issue tracker](#issue-tracker) - [Pull requests](#pull-requests) +- [Security vulnerabilities](#security-vulnerabilities) If you want to know how the GitLab team handles contributions have a look at [the GitLab contributing process](PROCESS.md). @@ -73,3 +74,6 @@ We will accept pull requests if: * It is a single commit (please use `git rebase -i` to squash commits) For examples of feedback on pull requests please look at already [closed pull requests](https://github.com/gitlabhq/gitlabhq/pulls?direction=desc&page=1&sort=created&state=closed). + +## Security vulnerabilities +Please report security vulnerabilities in private to support@gitlab.com; also see http://www.gitlab.com/disclosure/. Do NOT create GitHub issues for security vulnerabilities. -- cgit v1.2.1