From: Daniel Stenberg Date: Mon, 14 Jul 2025 06:59:04 +0000 (+0200) Subject: VULN-DISCLOSURE-POLICY.md: 7 days embargo is max X-Git-Tag: curl-8_15_0~24 X-Git-Url: http://git.ipfire.org/gitweb/gitweb.cgi?a=commitdiff_plain;h=af81e8fe5f45276877489d49e00cee874d4cd7bc;p=thirdparty%2Fcurl.git VULN-DISCLOSURE-POLICY.md: 7 days embargo is max It was recently updated in this doc to seven, but there were *two* numbers mentioned and only one of them was updated leaving the paragraph quite confusing. Follow-up to 83c90e50472f32b74e388f6e524d Closes #17921 --- diff --git a/docs/VULN-DISCLOSURE-POLICY.md b/docs/VULN-DISCLOSURE-POLICY.md index 9ed196f67f..00cdf86ec0 100644 --- a/docs/VULN-DISCLOSURE-POLICY.md +++ b/docs/VULN-DISCLOSURE-POLICY.md @@ -84,7 +84,7 @@ announcement. [distros@openwall](https://oss-security.openwall.org/wiki/mailing-lists/distros) to prepare them about the upcoming public security vulnerability announcement - attach the advisory draft for information with CVE and - current patch. 'distros' does not accept an embargo longer than 14 days and + current patch. 'distros' does not accept an embargo longer than 7 days and they do not care for Windows-specific flaws. - No more than 48 hours before the release, the private branch is merged into