Skip to content

Commit 8ea5ee9

Browse files
authored
Update security policy with reporting guidelines (#8284)
Added warnings about reporting issues and AI-related exploits.
1 parent 61b02bb commit 8ea5ee9

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
# Security Policy
22

3+
:warning: Do not report memory or resource leaks as security issues or exploits. Those are bugs. Report them via [Issues](https://github.com/ReactiveX/RxJava/issues) or better yet, post a **Pull Request**.
4+
5+
:information_source: with the advent of AI tools, high star projects like ours are prime target for trophy hunters. If you spam our repo with miscategorized exploits given our context, you will be banned after 1-3 warnings.
6+
37
If you have discovered a security vulnerability in this project, please report it privately. **Do not disclose it as a public issue.** This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.
48

59
Please disclose it at [security advisory](https://github.com/ReactiveX/RxJava/security/advisories/new).

0 commit comments

Comments
 (0)