DEVELOPMENT.md 363 B

Handling Security Reports

When receiving a vulnerability report:

  1. Acknowledge receipt within 48 hours
  2. Work with Jenkins Security Team if needed
  3. Prepare a fix in a private repository if necessary
  4. Coordinate disclosure timing
  5. Release an updated version following Jenkins security release process