mirror of
https://github.com/mruby/mruby
synced 2026-06-08 16:11:16 +00:00
696226a60e
Previously for lists we were using both `*` and `-` to start the list items. This pr changes all lists to use `-`.
21 lines
554 B
Markdown
21 lines
554 B
Markdown
# Security Policy
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
If you have any security concern, contact <matz@ruby.or.jp>.
|
|
|
|
## Scope
|
|
|
|
We consider the following issues as vulnerabilities:
|
|
|
|
- Remote code execution
|
|
- Crash caused by a valid Ruby script
|
|
|
|
We *don't* consider the following issues as vulnerabilities:
|
|
|
|
- Runtime C undefined behavior (including integer overflow)
|
|
- Crash caused by misused API
|
|
- Crash caused by modified compiled binary
|
|
- ASAN/Valgrind warning for too big memory allocation
|
|
mruby assumes `malloc(3)` returns `NULL` for too big allocations
|