[PATCH] Reword statement about filing private security issues

Siddhesh Poyarekar siddhesh@gotplt.org
Wed Jul 2 16:07:54 GMT 2025


I'll commit this shortly, hopefully it reflects what you suggested.  The
trailing '/' was a typo :)

Thanks,
Sid

--->8---

The "file a private bug" in the context of that paragraph can be
misleading, so reword it to make it clear that one needs to privately
email the glibc CNA to file a security issue.

Signed-off-by: Siddhesh Poyarekar <siddhesh@gotplt.org>
---
 security.html | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/security.html b/security.html
index 9916098..dc22ce6 100644
--- a/security.html
+++ b/security.html
@@ -82,12 +82,12 @@ network or can be used for local privilege escalation (through existing
 applications, not synthetic test cases) should be reported privately. We
 expect that such critical security bugs are rare, and that most security
 bugs can be reported in Bugzilla, thus making them public immediately.
-If in doubt, you can file a private bug.
-/<p>
+If in doubt, report the issue privately, as indicated below.
+</p>
 
 <p>
-If you want to report a <u>private</u> security bug, please contact the
-security team at
+If you want to report a <u>private</u> security issue, please contact
+the security team at
 <a href="glibc-cna@sourceware.org">glibc-cna@sourceware.org</a>. If you
 would like to encrypt communication about the security issue, you may
 use the <a href="#keys">GPG keys</a> of the security team members and
-- 
2.50.0



More information about the Libc-alpha mailing list