Skip to content

adjust the response time for vulnerability report #54

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
bjohansebas opened this issue Feb 24, 2025 · 0 comments · Fixed by expressjs/.github#15
Closed

adjust the response time for vulnerability report #54

bjohansebas opened this issue Feb 24, 2025 · 0 comments · Fixed by expressjs/.github#15

Comments

@bjohansebas
Copy link
Member

In our security policy, it states that we will get in touch within 48 hours after a vulnerability has been reported. I believe this is a short timeframe, considering that reports can be made over the weekend, and I don’t think many of us as maintainers would want to be available on a weekend. Perhaps we should consider extending the response time for such reports or improving the message to specify business days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant