Proposed security disclosure policy

Thank you everyone! I have a PR here: https://github.com/rust-lang/rust-www/pull/123

I believe that I’ve addressed everything that’s come up. Please let me know how this looks!

1 Like

We really need to spell out what a security problem is. Is this about rustc the application, or rust the language?

The language (soundness bugs in rustc the language can cause security bugs in other applications); though if the application has a security bug we should use this too.

Ok, so then issue 25549 would qualify as a security bug (it enables violation of memory safety)? It was reported yesterday.

Edit: Now fixed :ballot_box_with_check:

2 Likes

Yes. Sounds like it.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.