|
@@ -0,0 +1,20 @@
|
|
|
+How to Report a Potential Vulnerability?
|
|
|
+========================================
|
|
|
+
|
|
|
+If you would like to report a public issue (for example, one with a released
|
|
|
+CVE number), please report it to the mailing list:
|
|
|
+
|
|
|
+ https://lists.openembedded.org/g/openembedded-devel
|
|
|
+
|
|
|
+If you are dealing with a not-yet released or urgent issue, please send a
|
|
|
+message to one of the maintainers listed in the README. Include as many
|
|
|
+details as possible:
|
|
|
+ - the layer or software module affected
|
|
|
+ - the recipe and its version
|
|
|
+ - any example code, if available
|
|
|
+
|
|
|
+Branches maintained with security fixes
|
|
|
+---------------------------------------
|
|
|
+
|
|
|
+See https://wiki.yoctoproject.org/wiki/Releases for the list of current
|
|
|
+releases. We only accept patches for the LTS releases and the master branch.
|