_content/doc/security: request reporters to include preferred attribution Also fix typo and reword surrounding area for hopefully better clarity. Change-Id: I787d5ce95856db879afbfd629bfee5ae6a6a6964 Reviewed-on: https://go-review.googlesource.com/c/website/+/822367 Reviewed-by: Nicholas Husin <husin@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Damien Neil <dneil@google.com> Auto-Submit: Nicholas Husin <nsh@golang.org>
diff --git a/_content/doc/security/policy.md b/_content/doc/security/policy.md index 5cf8efe..d1c6c50 100644 --- a/_content/doc/security/policy.md +++ b/_content/doc/security/policy.md
@@ -19,19 +19,18 @@ {one-line summary}", and avoid sending attachments in your email unless strictly necessary in order to avoid your message being marked as spam. -Please keep reports succint, including a description of the issue you've found, +If desired, please include your preferred attribution as part of the report. +This attribution will be added to the CVE, if one is published. + +Please keep reports succinct, including a description of the issue you've found, the way in which you believe it can be exploited, and a small reproduction test case or program which demonstrates the issue. We have a [list of decisions](/doc/security/decisions) about commonly-reported categories of issues. -Your email will be acknowledged within 7 days, and you'll be kept up to date -with the progress until resolution. Your issue will be fixed or made public -within 90 days. - -If you have not received a reply to your email within 7 days, please follow up -with the Go Security team again at +Your email will be acknowledged within 7 days. If you have not received a reply +by then, please follow up with the Go Security team again at [security@golang.org](mailto:security@golang.org). Please make sure the word **vulnerability** is in your email. @@ -41,6 +40,9 @@ report a technical security or an abuse risk related bug in a Google product (SQLi, XSS, etc.)"_, and list _"Go"_ as the affected product. +Your issue will be fixed or made public within 90 days after our initial +acknowledgement. + ## Tracks Depending on the nature of your issue, it will be categorized by the Go