From bb6c5fad2458a47b4bed35ebd9188224ff1968f2 Mon Sep 17 00:00:00 2001 From: Flavio Leitner Date: Wed, 7 Jan 2015 14:26:40 -0200 Subject: [PATCH] SECURITY.md: contributors must agree to confidentiality There is no point in having the special process if a contributor refuses or doesn't agree with the confidentiality terms. Signed-off-by: Flavio Leitner Signed-off-by: Ben Pfaff --- SECURITY.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index e1db4cb68..e66a43f28 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -108,8 +108,7 @@ Steps 3a and 3b may proceed in parallel. The security team develops and obtains (private) reviews for patches that fix the vulnerability. If necessary, the security team pulls in -additional developers, who should be asked to maintain -confidentiality. +additional developers, who must agree to maintain confidentiality. Step 4: Embargoed Disclosure -- 2.20.1