updated the security policy of the project

This commit is contained in:
Gani Georgiev
2026-05-26 09:49:30 +03:00
parent b65b7c5c56
commit a7dfbbb8ec
2 changed files with 3068 additions and 3046 deletions
+8
View File
@@ -84,6 +84,14 @@ In many places where applicable we've tried to minimize the impact by using cons
If you think that there is a place where we can improve the handling without hurting too much the user experience, feel free to open a regular public issue and it will be considered.
</details>
<details>
<summary><strong>Attack-vectors relying on social engineering</strong></summary>
Reports for attacks relying on various social engineering tactics _(e.g. tricking someone to click on a link)_ are valid concerns but usually out of the security scope of the project as there are a lot of cases where this behavior is deliberate for better UX.
If you have concerns for such attack, feel free to open a regular public issue and we can eventually try to reconsider adding extra guards when feasible _(or at least properly document the existing behavior)_.
</details>
<details>
<summary><strong><code>disintegration/imaging</code> CVE-2023-36308</strong></summary>
File diff suppressed because it is too large Load Diff