From 83c90e50472f32b74e388f6e524d8584945cc866 Mon Sep 17 00:00:00 2001 From: Daniel Stenberg Date: Sat, 31 May 2025 17:46:19 +0200 Subject: [PATCH] VULN-DISCLOSURE-POLICY.md: the distros list wants <= 7 days embargo Closes #17497 --- docs/VULN-DISCLOSURE-POLICY.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/VULN-DISCLOSURE-POLICY.md b/docs/VULN-DISCLOSURE-POLICY.md index 23deb6b8fa..9dd349298e 100644 --- a/docs/VULN-DISCLOSURE-POLICY.md +++ b/docs/VULN-DISCLOSURE-POLICY.md @@ -80,7 +80,7 @@ announcement. Bounty team and the reporter is asked to request the reward from them after the issue has been completely handled and published by curl. -- No more than 10 days before release, inform +- No more than seven days before release, inform [distros@openwall](https://oss-security.openwall.org/wiki/mailing-lists/distros) to prepare them about the upcoming public security vulnerability announcement - attach the advisory draft for information with CVE and -- 2.47.3