mirror of
https://github.com/curl/curl.git
synced 2025-03-19 15:40:42 +08:00
VULN-DISCLOSURE-POLICY.md: update detail about CVE requests
curl is a CNA now Closes #13088
This commit is contained in:
parent
a586b8ca40
commit
39173f66e5
1
.github/scripts/spellcheck.words
vendored
1
.github/scripts/spellcheck.words
vendored
@ -117,6 +117,7 @@ cmake
|
||||
CMake's
|
||||
cmake's
|
||||
CMakeLists
|
||||
CNA
|
||||
CodeQL
|
||||
codeql
|
||||
CODESET
|
||||
|
@ -59,7 +59,8 @@ announcement.
|
||||
[SECURITY-ADVISORY](https://curl.se/dev/advisory.html) for help on creating
|
||||
the advisory.
|
||||
|
||||
- Request a CVE number from HackerOne
|
||||
- Request a CVE Id for the issue. curl is a CNA (CVE Numbering Authority) and
|
||||
can request its own numbers.
|
||||
|
||||
- Update the "security advisory" with the CVE number.
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user