diff --git a/SECURITY.md b/SECURITY.md index 0a4ce07456..e5904a5dcf 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -13,7 +13,7 @@ To report security vulnerabilities, open a normal bug report in the Additionally, you can use GitHub Private security advisories against this repository to report issues. -Note that I will respond to security communication within 72 hours. Once +Note that I will generally respond to security communication within 72 hours. Once the bug is confirmed, it will be fixed or at least mitigated within another 72 hours, at which time the fix will typically be committed to master and hence be public. That timeline might be extended based on the severity of the issue and the