mirror of
https://github.com/mruby/mruby
synced 2026-06-08 16:11:16 +00:00
SECURITY.md: add scope description.
This commit is contained in:
+13
@@ -3,3 +3,16 @@
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you have any security concern, contact <matz@ruby.or.jp>.
|
||||
|
||||
## Scope
|
||||
|
||||
We consider following issues as vulnerabilities:
|
||||
|
||||
* Remote code execution
|
||||
* Crash caused by a valid Ruby script
|
||||
|
||||
We *don't* consider following issues as vulnerabilities:
|
||||
|
||||
* Runtime C undefined behavior (including integer overflow)
|
||||
* Crash caused by misused API
|
||||
* Crash caused by tweaked compiled binary
|
||||
|
||||
Reference in New Issue
Block a user