We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent c8d60a2 commit 48f0ae2Copy full SHA for 48f0ae2
SECURITY.md
@@ -20,6 +20,14 @@ bottom of this file.
20
21
[security-gpg]: https://riot-os.org/assets/keys/security.asc
22
23
+### Classification of a vulnerability
24
+
25
+Unless the reporter explicitly requests not to do so,
26
+the RIOT security maintainers may declassify an issue
27
+if the issue is not deemed critical --
28
+for example when it requires an unlikely combination of circumstances and/or configuration options,
29
+or when it can only be exploited by a user who gains no additional privileges.
30
31
## Notification of a Vulnerability
32
33
After a fix is provided the security issue will be privately disclosed to the
0 commit comments