From ce4b017ab0c509218c9fceef71174711aff92801 Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Tue, 6 Dec 2022 17:28:52 -0500 Subject: [PATCH] Updates the security procedure to utilize github advisories for announcement. Per discussion at wg-backend meeting earlier today, -announce just isn't appropriate for this kind of message. --- SECURITY.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 77928a15c5b..94f8012ac9e 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -54,7 +54,7 @@ embargo, we will: - Patch the oldest release within the 12 month support window, and merge that fix forward. - Updates will be available on the `release_XX.YY` branches. - Update each release branch -- Post a notice to the [galaxy-announce mailing list](https://lists.galaxyproject.org/listinfo/galaxy-announce) with: +- Publish a security advisory on GitHub containing: - A description of the issue - List of supported versions that are affected - Steps to update or patch your Galaxy