aboutsummaryrefslogtreecommitdiffstats
path: root/docs/BUGS
diff options
context:
space:
mode:
authorHaibo Huang <hhb@google.com>2019-05-22 00:50:27 -0700
committerHaibo Huang <hhb@google.com>2019-05-23 21:56:48 -0700
commit34ab3465b2ef3c2ecf613738b94ff3fd8538d1e7 (patch)
treedef0cd4694db248f8c4d521c308102eb404252c2 /docs/BUGS
parent3ba998c1da1beee0fd5ff39891c723ac6f0936a0 (diff)
downloadexternal_curl-34ab3465b2ef3c2ecf613738b94ff3fd8538d1e7.tar.gz
external_curl-34ab3465b2ef3c2ecf613738b94ff3fd8538d1e7.tar.bz2
external_curl-34ab3465b2ef3c2ecf613738b94ff3fd8538d1e7.zip
Upgrade curl to curl-7_65_0
Test: build, boots, `vendor/google/tools/fake-ota on streaming` works Change-Id: I14034f7e81b55368c1927440cb2003b6b173a6f8
Diffstat (limited to 'docs/BUGS')
-rw-r--r--docs/BUGS11
1 files changed, 8 insertions, 3 deletions
diff --git a/docs/BUGS b/docs/BUGS
index 7322d9b2..480e0cae 100644
--- a/docs/BUGS
+++ b/docs/BUGS
@@ -61,9 +61,14 @@ BUGS
using our security development process.
Security related bugs or bugs that are suspected to have a security impact,
- should be reported by email to curl-security@haxx.se so that they first can
- be dealt with away from the public to minimize the harm and impact it will
- have on existing users out there who might be using the vulnerable versions.
+ should be reported on the curl security tracker at HackerOne:
+
+ https://hackerone.com/curl
+
+ This ensures that the report reaches the curl security team so that they
+ first can be deal with the report away from the public to minimize the harm
+ and impact it will have on existing users out there who might be using the
+ vulnerable versions.
The curl project's process for handling security related issues is
documented here: