Skip to content

Commit e5c0fba

Browse files
author
Daan Hoogland
committed
update expectation management
1 parent aee878b commit e5c0fba

1 file changed

Lines changed: 11 additions & 6 deletions

File tree

src/pages/security.md

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -39,12 +39,17 @@ team](https://www.apache.org/security/) via email to
3939
vulnerability, how it might be exploited, and any additional information that
4040
might be useful.
4141

42-
Upon notification, the ASF security team will work with the CloudStack PMC
43-
through validation and fixing the issue. If the issue is validated, it generally
44-
takes 2-4 weeks from notification to public announcement of the vulnerability.
45-
During this time, the team will communicate with you as they proceed through the
46-
response procedure, and ask that the issue not be announced before an
47-
agreed-upon date.
42+
Upon notification, the ASF security team will work with the CloudStack
43+
PMC through validation and fixing the issue. If the issue is
44+
validated, it will still take time to fix the issue. The amount of
45+
time depends on the availability of volunteers and number people
46+
involved that have a stake in the issue. In the past this would
47+
generally take 2-4 weeks from notification to public announcement of
48+
the vulnerability. In later years it has turned out to take more time
49+
(up to six months in some cases) due to parallel work on multiple
50+
issues. During this time, the team will communicate with you as they
51+
proceed through the response procedure, and ask that the issue not be
52+
announced before an agreed-upon date.
4853

4954
**Please do not create publicly-viewable JIRA tickets related to the issue**. If
5055
validated, a JIRA ticket with the security flag set will be created for tracking

0 commit comments

Comments
 (0)