Skip to content

Commit 4122c7d

Browse files
authored
docs: add security escalation policy (#5466)
1 parent 1164b9d commit 4122c7d

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

SECURITY.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,14 @@
55
To report a security vulnerability, please use the
66
[Tidelift security contact](https://tidelift.com/security).
77
Tidelift will coordinate the fix and disclosure.
8+
9+
## Escalation
10+
11+
If you do not receive an acknowledgement of your report
12+
within 6 business days, or if you cannot find a private
13+
security contact for the project, you may escalate to the
14+
OpenJS Foundation CNA at `[email protected]`.
15+
16+
If the project acknowledges your report but does not
17+
provide any further response or engagement within 14 days,
18+
escalation is also appropriate.

0 commit comments

Comments
 (0)