mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-09-24 21:30:12 +01:00
Also mentioned on DIscord [here](https://discord.com/channels/655572317891461132/707150492370862090/1229512261832409238) for context. The template may seen be people with commit access at https://github.com/carbon-language/carbon-lang/security/policy, by clicking "Start setup". We don't have any releases so I'm eliding support information there. This stems from the security policy advice at [OSSF](https://github.com/ossf/scorecard/blob/b118c1950f34e9d89237c1c6e69d273a192c490c/docs/checks.md#security-policy). It's common enough for these to be minimal ([step-security](https://github.com/step-security/harden-runner/security) is just an email address). I considered setting up a security list for Carbon, but not sure we need it at the moment; it seems slightly duplicative of the reporting which was previously enabled.
1.3 KiB
1.3 KiB
Security policy
It's important to us that the Carbon Language provides a secure implementation. Thank you for taking the time to report vulnerabilities.
The Carbon Language is still an experimental project, so please be careful if using it in security-sensitive environments.
Reporting a vulnerability
Please use https://github.com/carbon-language/carbon-lang/security/advisories/new to report security vulnerabilities.
We use GitHub's vulnerability reporting for intake. We will respond to reports within two weeks. For valid issues we will coordinate and disclose on GitHub.
If you haven't received a response, a couple steps to take are (in order):