From 7ea43bb25259b8e842ac5425a68900022a19683f Mon Sep 17 00:00:00 2001 From: Rossen Stoyanchev Date: Tue, 15 Oct 2024 17:13:29 +0100 Subject: [PATCH] Update SECURITY.md --- SECURITY.md | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index c08afbeb205..d92c8fa94f4 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,11 +1,10 @@ # Reporting a Vulnerability -You can create a [draft security advisory here](https://github.com/spring-projects/security-advisories/security/advisories/new). -Security issues must be disclosed and discussed in private. Please check out our [security policy](https://spring.io/security-policy). -Note that we can only accept vulnerabilities against [supported versions](https://spring.io/projects/spring-framework#support). +Please, [open a draft security advisory](https://github.com/spring-projects/security-advisories/security/advisories/new) if you need to disclose and discuss a security issue in private with the Spring Framework team. Note that we only accept reports against [supported versions](https://spring.io/projects/spring-framework#support). + +For more details, check out our [security policy](https://spring.io/security-policy). ## JAR signing Spring Framework JARs released on Maven Central are signed. You'll find more information about the key here: https://spring.io/GPG-KEY-spring.txt -