From 5835461b16376e2e26b0c35201fbd54dbe8c36b6 Mon Sep 17 00:00:00 2001 From: zzak Date: Fri, 3 May 2013 22:21:34 +0000 Subject: * doc/security.rdoc: Add note about reporting security vulns git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@40574 b2dd03c8-39d4-4d8f-98ff-823fe69b080e --- doc/security.rdoc | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'doc') diff --git a/doc/security.rdoc b/doc/security.rdoc index 9f4bca67c5..2cf6531785 100644 --- a/doc/security.rdoc +++ b/doc/security.rdoc @@ -10,6 +10,11 @@ Please check the full list of publicly known CVEs and how to correctly report a security vulnerability, at: http://www.ruby-lang.org/en/security/ Japanese version is here: http://www.ruby-lang.org/ja/security/ +Security vulnerabilities should be reported via an email to +mailto:security@ruby-lang.org ({the PGP public +key}[http://www.ruby-lang.org/security.asc]), which is a private mailing list. +Reported problems will be published after fixes. + == $SAFE Ruby provides a mechanism to restrict what operations can be performed by Ruby -- cgit v1.2.3