|
4 | 4 |
|
5 | 5 | Only the latest non beta release version of `nc_py_api` are currently being supported with security updates. |
6 | 6 |
|
7 | | -## Reporting a Vulnerability |
| 7 | +## Reporting a Vulnerability about nc_py_api |
8 | 8 |
|
9 | | -Security is very important to us. If you have discovered a security issue with Nextcloud, |
| 9 | +Officially, Nextcloud is not responsible for this project; the project is developed in the community’s free time. |
| 10 | + |
| 11 | +Please report security vulnerabilities to bigcat88@icloud.com with `nc-py-api` in the subject line. |
| 12 | +If there is no response within 24 hours, then create an Issue, |
| 13 | +without technical details, to report on the previously sent mail. |
| 14 | + |
| 15 | +## Reporting a Vulnerability about Nextcloud |
| 16 | + |
| 17 | +Transparency and Security are vital. |
| 18 | +If you have discovered a security issue with Nextcloud, |
10 | 19 | please read our responsible disclosure guidelines and contact us at [hackerone.com/nextcloud](https://hackerone.com/nextcloud). |
11 | 20 | Your report should include: |
12 | 21 |
|
13 | 22 | - Product version |
14 | 23 | - A vulnerability description |
15 | 24 | - Reproduction steps |
16 | 25 |
|
17 | | -If in scope of the project a member of the security team will confirm the vulnerability, determine its impact, and develop a fix. |
| 26 | +If in the scope of the project, a member of the security team confirms the vulnerability, determines its impact, and develops a fix. |
18 | 27 | Otherwise, the team will contact the maintainer and make sure the issue gets fixed. |
19 | 28 | The fix will be applied to the main branch, tested, and packaged in the next security release. |
20 | 29 | The vulnerability will be publicly announced after the release. |
21 | 30 |
|
22 | 31 | Finally, your name will be added to the [hall of fame](https://hackerone.com/nextcloud/thanks) |
23 | | -as a thank you from the entire Nextcloud community. |
| 32 | +as a thank-you from the entire Nextcloud community. |
24 | 33 |
|
25 | 34 | Note our [threat model](https://nextcloud.com/security/threat-model) to know what is expected behavior. |
26 | 35 |
|
|
0 commit comments