Skip to content

Commit 289a8e3

Browse files
RafaelGSSMoLow
authored andcommitted
doc: clarify reports are only evaluated on active versions
PR-URL: nodejs#47341 Reviewed-By: Richard Lau <rlau@redhat.com> Reviewed-By: Beth Griggs <bethanyngriggs@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
1 parent a8430ad commit 289a8e3

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

SECURITY.md

+6-5
Original file line numberDiff line numberDiff line change
@@ -31,11 +31,12 @@ maintainers.
3131
Here is the security disclosure policy for Node.js
3232

3333
* The security report is received and is assigned a primary handler. This
34-
person will coordinate the fix and release process. The problem is confirmed
35-
and a list of all affected versions is determined. Code is audited to find
36-
any potential similar problems. Fixes are prepared for all releases which are
37-
still under maintenance. These fixes are not committed to the public
38-
repository but rather held locally pending the announcement.
34+
person will coordinate the fix and release process. The problem is validated
35+
against all supported Node.js versions. Once confirmed, a list of all affected
36+
versions is determined. Code is audited to find any potential similar
37+
problems. Fixes are prepared for all supported releases.
38+
These fixes are not committed to the public repository but rather held locally
39+
pending the announcement.
3940

4041
* A suggested embargo date for this vulnerability is chosen and a CVE (Common
4142
Vulnerabilities and Exposures (CVE®)) is requested for the vulnerability.

0 commit comments

Comments
 (0)