Skip to content

Commit 13a2abc

Browse files
committed
clarifications added, typos fixed [ci skip]
Signed-off-by: Alexander Piskun <bigcat88@icloud.com>
1 parent 700ee3a commit 13a2abc

File tree

1 file changed

+13
-4
lines changed

1 file changed

+13
-4
lines changed

.github/SECURITY.md

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,23 +4,32 @@
44

55
Only the latest non beta release version of `nc_py_api` are currently being supported with security updates.
66

7-
## Reporting a Vulnerability
7+
## Reporting a Vulnerability about nc_py_api
88

9-
Security is very important to us. If you have discovered a security issue with Nextcloud,
9+
Officially, Nextcloud is not responsible for this project; the project is developed in the community’s free time.
10+
11+
Please report security vulnerabilities to bigcat88@icloud.com with `nc-py-api` in the subject line.
12+
If there is no response within 24 hours, then create an Issue,
13+
without technical details, to report on the previously sent mail.
14+
15+
## Reporting a Vulnerability about Nextcloud
16+
17+
Transparency and Security are vital.
18+
If you have discovered a security issue with Nextcloud,
1019
please read our responsible disclosure guidelines and contact us at [hackerone.com/nextcloud](https://hackerone.com/nextcloud).
1120
Your report should include:
1221

1322
- Product version
1423
- A vulnerability description
1524
- Reproduction steps
1625

17-
If in scope of the project a member of the security team will confirm the vulnerability, determine its impact, and develop a fix.
26+
If in the scope of the project, a member of the security team confirms the vulnerability, determines its impact, and develops a fix.
1827
Otherwise, the team will contact the maintainer and make sure the issue gets fixed.
1928
The fix will be applied to the main branch, tested, and packaged in the next security release.
2029
The vulnerability will be publicly announced after the release.
2130

2231
Finally, your name will be added to the [hall of fame](https://hackerone.com/nextcloud/thanks)
23-
as a thank you from the entire Nextcloud community.
32+
as a thank-you from the entire Nextcloud community.
2433

2534
Note our [threat model](https://nextcloud.com/security/threat-model) to know what is expected behavior.
2635

0 commit comments

Comments
 (0)