Skip to content

Commit 064437a

Browse files
authored
doc: clarify reports are only evaluated on active versions
1 parent b74b9dd commit 064437a

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

SECURITY.md

+4-3
Original file line numberDiff line numberDiff line change
@@ -31,9 +31,10 @@ maintainers.
3131
Here is the security disclosure policy for Node.js
3232

3333
* The security report is received and is assigned a primary handler. This
34-
person will coordinate the fix and release process. The problem is confirmed
35-
and a list of all affected versions is determined. Code is audited to find
36-
any potential similar problems. Fixes are prepared for all releases which are
34+
person will coordinate the fix and release process. The problem is validated
35+
against all active Node.js versions. Once confirmed a list of all affected
36+
versions is determined. Code is audited to find any potential similar
37+
problems. Fixes are prepared for all releases which are
3738
still under maintenance. These fixes are not committed to the public
3839
repository but rather held locally pending the announcement.
3940

0 commit comments

Comments
 (0)