Conversation
|
Hi @djc , thanks for the reminder. As I previously reported, the grace period would be 2 weeks after reporting issues in repo. If still no response, then we can go ahead to send the advisory. Isn't this the policy? Just for confirmation. |
It's more of a guideline than a policy, and it's not completely obvious that just pinging on GitHub is sufficient. |
Understood. I think I should also ask the approval for advisories rather than just publising the issue. Thanks! |
|
@shinmao we have no 2 week grace periods. The industry has generally settled on a 90 day window, but that's typically for private vulnerability disclosures |
|
@tarcieri gotcha! I will wait for the response from the maintainers. |
|
The closest we get is this:
|
The safe API, which has been reported with undefined behavior, can trigger UB again. It requires a more systematic fix on satisfying safety invariants.