mirror of
https://github.com/refraction-networking/uquic.git
synced 2025-04-03 20:27:35 +03:00
20 lines
1 KiB
Markdown
20 lines
1 KiB
Markdown
# Security Policy
|
|
|
|
quic-go still in development. This means that there may be problems in our protocols,
|
|
or there may be mistakes in our implementations.
|
|
We take security vulnerabilities very seriously. If you discover a security issue,
|
|
please bring it to our attention right away!
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
If you find a vulnerability that may affect live deployments -- for example, by exposing
|
|
a remote execution exploit -- please report privately to us by emailing one of the maintainers you can find in README.md.
|
|
|
|
In case the vulnerability is with the upstream [quic-go](https://github.com/quic-go/quic-go) (which is likely the case), please report it directly to them privately [here](https://github.com/quic-go/quic-go/security/advisories/new).
|
|
|
|
If the issue is an implementation weakness that cannot be immediately exploited or
|
|
something not yet deployed, just discuss it openly.
|
|
|
|
## Reporting a non security bug
|
|
|
|
For non-security bugs, please simply file a GitHub [issue](https://github.com/refraction-networking/uquic/issues/new).
|