You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+6-1Lines changed: 6 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,7 +10,7 @@ This repository contains a [devcontainer](https://docs.github.com/en/codespaces/
10
10
11
11
## State
12
12
13
-
This repository is under active development; see [pulse](https://github.com/philips-software/amp-devcontainer/pulse) for more details;
13
+
This repository is under active development; see [pulse](https://github.com/philips-software/amp-devcontainer/pulse) for more details.
14
14
15
15
## Description
16
16
@@ -62,6 +62,11 @@ See [CHANGELOG](./CHANGELOG.md) for more info on what's been changed.
62
62
63
63
See [CONTRIBUTING](./CONTRIBUTING.md)
64
64
65
+
## Reporting vulnerabilities
66
+
67
+
If you find a vulnerability, please report it to us!
68
+
See [SECURITY.md](./SECURITY.md) for more information.
The [latest](https://github.com/philips-software/amp-devcontainer/releases/latest) version of
6
+
amp-devcontainer is supported with security updates.
7
+
8
+
## Reporting a Vulnerability
9
+
10
+
If you find a significant vulnerability, or evidence of one, please report it privately.
11
+
12
+
Vulnerabilities should be reported using [GitHub's mechanism for privately reporting a vulnerability](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability). Under the
13
+
[main repository's security tab](https://github.com/philips-software/amp-devcontainer/security), click "Report a vulnerability" to open the advisory form.
14
+
15
+
A member of the amp-devcontainer team will triage the reported vulnerability and if the vulnerability is accepted a security advisory will be published and all further communication will be done via that security advisory.
0 commit comments