From 07bb0e894c1318460448370eb8db5a792feb2571 Mon Sep 17 00:00:00 2001 From: Bruno Oliveira da Silva Date: Thu, 14 Dec 2023 18:58:59 -0300 Subject: [PATCH] Update the security policy to prevent some back and forth with the community (#437) * Update the security policy to prevent some back and forth with the community * Adding a mention about third-party libraries Signed-off-by: Bruno Oliveira da Silva --- pages/security.ftl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pages/security.ftl b/pages/security.ftl index 3e286961..593058dc 100644 --- a/pages/security.ftl +++ b/pages/security.ftl @@ -11,7 +11,7 @@

It is important that suspected vulnerabilities are disclosed in a responsible way, and are not publicly disclosed until after they have been analysed and a fix is available.

-

To report a security vulnerability, send an email to keycloak-security@googlegroups.com.

+

To report a security vulnerability in the Keycloak codebase, send an email to keycloak-security@googlegroups.com. Please include the version affected, provide detailed instructions on how to reproduce the issue, and include your contact information for acknowledgements. If you are reporting known CVEs related to third-party libraries used in Keycloak, please create a new GitHub issue.

If you would like to work with us on a fix for the security vulnerability, please include your GitHub username in the above email, and we will provide you access to a temporary private fork where we can collaborate on a fix without it being disclosed publicly.