mirror of
https://github.com/alibaba/higress.git
synced 2026-05-26 21:57:30 +08:00
docs: add ASRC as supplementary vulnerability reporting channel in SECURITY.md
Change-Id: I52297cb7169a9997be08e8d4c69db599113d960a Co-developed-by: Kiro <noreply@kiro.dev> Signed-off-by: EndlessSeeker <1766508902@qq.com>
This commit is contained in:
@@ -17,12 +17,18 @@ your contributions.
|
|||||||
**Please do NOT report security vulnerabilities through public GitHub issues,
|
**Please do NOT report security vulnerabilities through public GitHub issues,
|
||||||
discussions, or pull requests.**
|
discussions, or pull requests.**
|
||||||
|
|
||||||
Instead, please report them through one of the following private channels:
|
Instead, please report them through one of the following private channels
|
||||||
|
(choose either one):
|
||||||
|
|
||||||
- **GitHub Private Security Advisory**:
|
- **GitHub Private Security Advisory**:
|
||||||
<https://github.com/higress-group/higress/security/advisories/new>
|
<https://github.com/higress-group/higress/security/advisories/new>
|
||||||
- **Email**: [higress@googlegroups.com](mailto:higress@googlegroups.com)
|
- **Email**: [higress@googlegroups.com](mailto:higress@googlegroups.com)
|
||||||
|
|
||||||
|
In addition, we recommend also reporting the vulnerability to the
|
||||||
|
[Alibaba Security Response Center (ASRC)](https://security.alibaba.com/),
|
||||||
|
as Higress is widely deployed on Alibaba Cloud infrastructure. Reporting to
|
||||||
|
ASRC helps ensure timely patching for cloud-hosted deployments.
|
||||||
|
|
||||||
Please include as much of the following information as possible to help us
|
Please include as much of the following information as possible to help us
|
||||||
triage and address the issue:
|
triage and address the issue:
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user