From 2c6d95507df0be38d5dab4692bda2fa364d2583c Mon Sep 17 00:00:00 2001 From: Peter van Dijk Date: Wed, 3 Feb 2021 08:46:24 +0100 Subject: [PATCH] docs security policy: steal OARC link&text from https://www.isc.org/security-report/ --- docs/common/security-policy.rst | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/common/security-policy.rst b/docs/common/security-policy.rst index ac7bf33b11..fbbbd34700 100644 --- a/docs/common/security-policy.rst +++ b/docs/common/security-policy.rst @@ -10,6 +10,8 @@ We fully credit reporters of security issues, and respond quickly, but please al We remind PowerDNS users that under the terms of the GNU General Public License, PowerDNS comes with ABSOLUTELY NO WARRANTY. This license is included in this documentation. +If you believe you have found a security vulnerability that applies to DNS implementations generally, and you want to report this responsibly to a number of implementers, you might consider also using the `Open Source DNS Vulnerability mailing list `_, managed by `DNS-OARC `_. + HackerOne ^^^^^^^^^ Security issues can also be reported on `our HackerOne page `_ and might fetch a bounty. -- 2.47.2