glamod / cdm_reader_mapper

MIT License
1 stars 5 forks source link

Vulnerability report process #53

Open ludwiglierhammer opened 3 months ago

ludwiglierhammer commented 3 months ago

It is recommended to create a security policy that includes a mail address to contact if one have found a security vulnerability in order to follow best practices for Free/Libre and Open Source Software (FLOSS) projects.

As an example you can have a look on xclim's security policy.

@aanderss, @rcornes Do we have a mail address to contact in this case?

rcornes commented 3 months ago

As project lead this should be a DWD address