]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
docs: update security policy to suggest GH advisories
authorLuca Boccassi <luca.boccassi@gmail.com>
Tue, 17 Mar 2026 18:26:04 +0000 (18:26 +0000)
committerLuca Boccassi <luca.boccassi@gmail.com>
Wed, 18 Mar 2026 10:36:43 +0000 (10:36 +0000)
docs/SECURITY.md

index f9f2e91ad681e8a2e77ea1da74c9db770a41ef76..0993f85da2bb651d9567a499f419660ebe7fe208 100644 (file)
@@ -8,11 +8,13 @@ SPDX-License-Identifier: LGPL-2.1-or-later
 # Reporting of Security Vulnerabilities
 
 If you discover a security vulnerability, we'd appreciate a non-public disclosure.
-systemd developers can be contacted privately on the **[systemd-security@redhat.com](mailto:systemd-security@redhat.com) mailing list**.
+systemd developers can be contacted privately by creating a new **[Security Advisory on GitHub](https://github.com/systemd/systemd/security/advisories/new)**
+or via the **[systemd-security@redhat.com](mailto:systemd-security@redhat.com) mailing list**.
 The disclosure will be coordinated with distributions.
 
 (The [issue tracker](https://github.com/systemd/systemd/issues) and [systemd-devel mailing list](https://lists.freedesktop.org/mailman/listinfo/systemd-devel) are fully public.)
 
-Subscription to the systemd-security mailing list is open to **regular systemd contributors and people working in the security teams of various distributions**.
+Subscription to the Security Advisories and/or systemd-security mailing list is open to **regular systemd contributors and people working in the security teams of various distributions**.
 Those conditions should be backed by publicly accessible information (ideally, a track of posts and commits from the mail address in question).
-If you fall into one of those categories and wish to be subscribed, submit a **[subscription request](https://www.redhat.com/mailman/listinfo/systemd-security)**.
+If you fall into one of those categories and wish to be subscribed,
+contact the maintainers or submit a **[subscription request](https://www.redhat.com/mailman/listinfo/systemd-security)**.