Skip to content

Commit 519b3d1

Browse files
authored
docs: add security escalation policy (#6025)
1 parent 61ff26e commit 519b3d1

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

SECURITY.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,3 +33,9 @@ directly to the Lodash maintainers through the [Security tab](https://github.com
3333
repository.
3434

3535
Your efforts to responsibly disclose your findings are sincerely appreciated.
36+
37+
## Escalation
38+
39+
If you do not receive an acknowledgement of your report within 6 business days, or if you cannot find a private security contact for the project, you may escalate to the OpenJS Foundation CNA at `[email protected]`.
40+
41+
If the project acknowledges your report but does not provide any further response or engagement within 14 days, escalation is also appropriate.

0 commit comments

Comments
 (0)