Handling Security Reports
When receiving a vulnerability report:
- Acknowledge receipt within 48 hours
- Work with Jenkins Security Team if needed
- Prepare a fix in a private repository if necessary
- Coordinate disclosure timing
- Release an updated version following Jenkins security release process