SECURITY.md: add scope description.

parent d96f53f8
......@@ -3,3 +3,16 @@
## Reporting a Vulnerability
If you have any security concern, contact <matz@ruby.or.jp>.
## Scope
We consider following issues as vulnerabilities:
* Remote code execution
* Crash caused by a valid Ruby script
We *don't* consider following issues as vulnerabilities:
* Runtime C undefined behavior (including integer overflow)
* Crash caused by misused API
* Crash caused by tweaked compiled binary
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment