Commit: please report security issues to the vim-security list

10 views
Skip to first unread message

Christian Brabandt

unread,
Oct 23, 2023, 2:15:08 PM10/23/23
to vim...@googlegroups.com
please report security issues to the vim-security list

Commit: https://github.com/vim/vim/commit/50f3ec2898a43feaa6add2bc4875754cf9224d5e
Author: Christian Brabandt <c...@256bit.org>
Date: Mon Oct 23 19:59:22 2023 +0200

please report security issues to the vim-security list

Signed-off-by: Christian Brabandt <c...@256bit.org>

diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml
index 3c9742093..d1acf94df 100644
--- a/.github/ISSUE_TEMPLATE/bug_report.yml
+++ b/.github/ISSUE_TEMPLATE/bug_report.yml
@@ -9,8 +9,10 @@ body:
value: |
Thanks for reporting issues of Vim!

- If you want to report a security issue, instead of reporting it here
- please disclose it privately to c...@256bit.org
+ If you want to report a security issue, instead of reporting it here publicly,
+ please disclose it privately via mail to vim-se...@googlegroups.com.
+ (It's a private list read only by the maintainers,
+ but anybody can post, after moderation.)

To make it easier for us to help you please enter detailed information below.
- type: textarea
diff --git a/SECURITY.md b/SECURITY.md
index 67548bb00..7d1e0166c 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -2,6 +2,9 @@

## Reporting a vulnerability

-If you want to report a security issue, please privately disclose the issue to the current maintainer c...@256bit.org
+If you want to report a security issue, please privately disclose the issue to the vim-security mailing list
+vim-se...@googlegroups.com
+
+This is a private list, read only by the maintainers, but anybody can post, after moderation.

**Please don't publicly disclose the issue until it has been addressed by us.**
Reply all
Reply to author
Forward
0 new messages