Skip to content

Commit f4ec250

Browse files
authored
Update SECURITY.md
1 parent 09b9617 commit f4ec250

File tree

1 file changed

+30
-13
lines changed

1 file changed

+30
-13
lines changed

SECURITY.md

Lines changed: 30 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,39 @@
11

2-
## MyToDoReact version 1.0.
3-
##
4-
## Copyright (c) 2021 Oracle, Inc.
5-
## Licensed under the Universal Permissive License v 1.0 as shown at https://oss.oracle.com/licenses/upl/
6-
# Reporting Security Vulnerabilities
2+
# Reporting security vulnerabilities
73

8-
Oracle values the independent security research community and believes that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of all our users.
4+
Oracle values the independent security research community and believes that
5+
responsible disclosure of security vulnerabilities helps us ensure the security
6+
and privacy of all our users.
97

10-
Please do NOT raise a GitHub Issue to report a security vulnerability. If you believe you have found a security vulnerability, please submit a report to [secalert\_us@oracle.com](mailto:secalert_us@oracle.com) preferably with a proof of concept. We provide additional information on [how to report security vulnerabilities to Oracle](https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html) which includes public encryption keys for secure email.
8+
Please do NOT raise a GitHub Issue to report a security vulnerability. If you
9+
believe you have found a security vulnerability, please submit a report to
10+
[secalert_us@oracle.com][1] preferably with a proof of concept. Please review
11+
some additional information on [how to report security vulnerabilities to Oracle][2].
12+
We encourage people who contact Oracle Security to use email encryption using
13+
[our encryption key][3].
1114

12-
We ask that you do not use other channels or contact project contributors directly.
15+
We ask that you do not use other channels or contact the project maintainers
16+
directly.
1317

14-
Non-vulnerability related security issues such as new great new ideas for security features are welcome on GitHub Issues.
18+
Non-vulnerability related security issues including ideas for new or improved
19+
security features are welcome on GitHub Issues.
1520

16-
### Security Updates, Alerts and Bulletins
21+
## Security updates, alerts and bulletins
1722

18-
Security updates will be released on a regular cadence. Many of our projects will typically release security fixes in conjunction with the [Oracle Critical Patch Update](https://www.oracle.com/security-alerts/) program. Security updates are released on the Tuesday closest to the 17th day of January, April, July and October. A pre-release announcement will be published on the Thursday preceding each release. Additional information, including past advisories, is available on our [Security Alerts](https://www.oracle.com/security-alerts/) page.
23+
Security updates will be released on a regular cadence. Many of our projects
24+
will typically release security fixes in conjunction with the
25+
[Oracle Critical Patch Update][3] program. Additional
26+
information, including past advisories, is available on our [security alerts][4]
27+
page.
1928

20-
### Security-Related Information
29+
## Security-related information
2130

22-
We will provide security related information such as a threat model, considerations for secure use, or any known security issues in our documentation. Please note that labs and sample code are intended to demonstrate a concept and may not be sufficiently hardened for production use.
31+
We will provide security related information such as a threat model, considerations
32+
for secure use, or any known security issues in our documentation. Please note
33+
that labs and sample code are intended to demonstrate a concept and may not be
34+
sufficiently hardened for production use.
35+
36+
[1]: mailto:secalert_us@oracle.com
37+
[2]: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
38+
[3]: https://www.oracle.com/security-alerts/encryptionkey.html
39+
[4]: https://www.oracle.com/security-alerts/

0 commit comments

Comments
 (0)