Skip to content

Commit 48f0ae2

Browse files
committed
SECURITY: Describe that declassification is an option
1 parent c8d60a2 commit 48f0ae2

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

SECURITY.md

+8
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,14 @@ bottom of this file.
2020

2121
[security-gpg]: https://riot-os.org/assets/keys/security.asc
2222

23+
### Classification of a vulnerability
24+
25+
Unless the reporter explicitly requests not to do so,
26+
the RIOT security maintainers may declassify an issue
27+
if the issue is not deemed critical --
28+
for example when it requires an unlikely combination of circumstances and/or configuration options,
29+
or when it can only be exploited by a user who gains no additional privileges.
30+
2331
## Notification of a Vulnerability
2432

2533
After a fix is provided the security issue will be privately disclosed to the

0 commit comments

Comments
 (0)