diff --git a/SECURITY.md b/SECURITY.md index c474eb7f4bde8..7bd3ead079fbd 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,3 +1,3 @@ # Security Policy -The security policy and supported versions are outlined on the Pulsar website here: https://pulsar.apache.org/docs/security-policy-and-supported-versions/. \ No newline at end of file +The security policy and supported versions are outlined on the Pulsar website here: https://pulsar.apache.org/docs/security-policy-and-supported-versions/. diff --git a/site2/docs/security-policy-and-supported-versions.md b/site2/docs/security-policy-and-supported-versions.md index 233686507770e..ac907e12c7006 100644 --- a/site2/docs/security-policy-and-supported-versions.md +++ b/site2/docs/security-policy-and-supported-versions.md @@ -14,6 +14,12 @@ https://pulsar.apache.org/docs/en/security-overview/. The Pulsar community will announce security vulnerabilities and how to mitigate them on the [users@pulsar.apache.org](mailto:users@pulsar.apache.org). For instructions on how to subscribe, please see https://pulsar.apache.org/contact/. +## Reporting Vulnerabilities + +The Pulsar community follows the ASF [vulnerability handling process](https://apache.org/security/#vulnerability-handling). + +To report a new vulnerability you have discovered please follow the [ASF vulnerability reporting process](https://apache.org/security/#reporting-a-vulnerability). + ## Versioning Policy The Pulsar project adheres to [Semantic Versioning](http://semver.org/spec/v2.0.0.html). Existing releases can expect