rubysec.github.io
rubysec.github.io copied to clipboard
Current home of rubysec.com
Document the steps to report a vulnerability. 1. OSVDB: email [email protected] and/or message @osvdb on GitHub or Twitter. 2. Request a CVE from oss-sec mailing list or reserve a CVE...
Most gems don't have any set process/policy for handling security vulnerabilities. We should provide a basic template for them to use to make it easier for them to draft one...
Add a template for Advisories, based off of the standard Rails Security advisory.