diff --git a/.github/ISSUE_TEMPLATE.md b/.github/ISSUE_TEMPLATE.md index 956db4bd79f..19c022f10be 100644 --- a/.github/ISSUE_TEMPLATE.md +++ b/.github/ISSUE_TEMPLATE.md @@ -1,20 +1,20 @@ \ No newline at end of file +--> diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 846566bce19..e80dddd0cf8 100755 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -25,6 +25,14 @@ problem. +== Reporting Security Vulnerabilities +If you think you have found a security vulnerability in Spring Boot please *DO NOT* +disclose it publicly until we've had a chance to fix it. Please don't report security +vulnerabilities using GitHub issues, instead head over to https://pivotal.io/security and +learn how to disclose them responsibly. + + + == Sign the Contributor License Agreement Before we accept a non-trivial patch or pull request we will need you to https://cla.pivotal.io/sign/spring[sign the Contributor License Agreement].