Skip to content

Commit cfa7e4c

Browse files
committed
Merge pull request symfony#2696 from fabpot/security-tweaks
added some more information about the security process
2 parents 7ae32e2 + 4e7472c commit cfa7e4c

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

contributing/code/security.rst

+4-2
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,9 @@ solve the issue via pull requests, code reviews, and comments;
7575

7676
4. Once the fix is found, all involved projects collaborate to find the best
7777
date for a joint release (there is no guarantee that all releases will be at
78-
the same time but we will try hard to make them at about the same time).
78+
the same time but we will try hard to make them at about the same time). When
79+
the issue is not known to be exploited in the wild, a period of two weeks
80+
seems like a reasonable amount of time.
7981

8082
The list of downstream projects participating in this process is kept as small
8183
as possible in order to better manage the flow of confidential information
@@ -85,7 +87,7 @@ the Symfony security team.
8587
As of today, the following projects have validated this process and are part
8688
of the downstream projects included in this process:
8789

88-
* Drupal
90+
* Drupal (releases typically happen on Wednesdays)
8991
* eZPublish
9092

9193
Security Advisories

0 commit comments

Comments
 (0)