xref: /aosp_15_r20/external/fonttools/SECURITY.md (revision e1fe3e4ad2793916b15cccdc4a7da52a7e1dd0e9)
1*e1fe3e4aSElliott Hughes# Security Policy
2*e1fe3e4aSElliott Hughes
3*e1fe3e4aSElliott HughesIf you have discovered a security vulnerability in this project, please report it
4*e1fe3e4aSElliott Hughesprivately. **Do not disclose it as a public issue.** This gives us time to work with you
5*e1fe3e4aSElliott Hughesto fix the issue before public exposure, reducing the chance that the exploit will be
6*e1fe3e4aSElliott Hughesused before a patch is released.
7*e1fe3e4aSElliott Hughes
8*e1fe3e4aSElliott HughesYou may submit the report in the following ways:
9*e1fe3e4aSElliott Hughes
10*e1fe3e4aSElliott Hughes- send an email to [email protected], [email protected] and [email protected]; and/or
11*e1fe3e4aSElliott Hughes- send us a [private vulnerability report](https://github.com/fonttools/fonttools/security/advisories/new)
12*e1fe3e4aSElliott Hughes
13*e1fe3e4aSElliott HughesPlease provide the following information in your report:
14*e1fe3e4aSElliott Hughes
15*e1fe3e4aSElliott Hughes- A description of the vulnerability and its impact
16*e1fe3e4aSElliott Hughes- How to reproduce the issue
17*e1fe3e4aSElliott Hughes
18*e1fe3e4aSElliott HughesPlease allow us 90 days to work on a fix before public disclosure.
19