summaryrefslogtreecommitdiff
path: root/INSTALL
diff options
context:
space:
mode:
authorNicholas Clark <nick@ccl4.org>2008-12-06 15:07:55 +0000
committerNicholas Clark <nick@ccl4.org>2008-12-06 15:07:55 +0000
commit5acb7768560c2784f756ed5cfc88162c6759ce4e (patch)
tree4d60d43fd55ff9f691e2d99fc7eec3263cd004ed /INSTALL
parentadc423160116ecb9496dc37182c54ecac309855c (diff)
downloadperl-5acb7768560c2784f756ed5cfc88162c6759ce4e.tar.gz
Note perl5-security-report@perl.org in INSTALL. Must remember to
mention it in the release announcement. p4raw-id: //depot/perl@35039
Diffstat (limited to 'INSTALL')
-rw-r--r--INSTALL9
1 files changed, 9 insertions, 0 deletions
diff --git a/INSTALL b/INSTALL
index 80a1f309e2..88525b94e3 100644
--- a/INSTALL
+++ b/INSTALL
@@ -2205,6 +2205,15 @@ attachments or encodings may actually reduce the number of people who
read your message. Your message will get relayed to over 400
subscribers around the world so please try to keep it brief but clear.
+If the bug you are reporting has security implications, which make it
+inappropriate to send to a publicly archived mailing list, then please send
+it to perl5-security-report@perl.org. This points to a closed subscription
+unarchived mailing list, which includes all the core committers, who be able
+to help assess the impact of issues, figure out a resolution, and help
+co-ordinate the release of patches to mitigate or fix the problem across all
+platforms on which Perl is supported. Please only use this address for security
+issues in the Perl core, not for modules independently distributed on CPAN.
+
If you are unsure what makes a good bug report please read "How to
report Bugs Effectively" by Simon Tatham:
http://www.chiark.greenend.org.uk/~sgtatham/bugs.html