Description
We activated the private vulnerability reports as part of our participation in the GitHub Secure Fund program. We should also document both privately and internally the incidence response plan to set expectations on how to act when a vulnerability is reported.
Description
We activated the private vulnerability reports as part of our participation in the GitHub Secure Fund program. We should also document both privately and internally the incidence response plan to set expectations on how to act when a vulnerability is reported.