18F / open-source-policy

This repository contains the official Open Source Policy of 18F
https://18f.gsa.gov
Other
298 stars 94 forks source link

Clarifying definition of a public vulnerability #64

Closed brittag closed 7 years ago

brittag commented 7 years ago

Under the definition of "Undisclosed vulnerabilities", "isn't easy to find with scanning tools" was a bit subjective, so here's a suggested improvement: "can't be found with a publicly-available open source scanning tool run on the public-facing system".

cc @wslack @afeld @NoahKunin @konklone as people who may have opinions