Skip to content

Commit 62249da

Browse files
committed
docs: Note team members, add a link to SECURITY.md, add slack channel
Signed-off-by: Russell Bryant <[email protected]>
1 parent 0e116c1 commit 62249da

File tree

2 files changed

+10
-2
lines changed

2 files changed

+10
-2
lines changed

SECURITY.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44

55
If you believe you have found a security vulnerability in vLLM, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.
66

7-
Please report security issues privately using [the vulnerability submission form](https://github.com/vllm-project/vllm/security/advisories/new).
7+
Please report security issues privately using [the vulnerability submission form](https://github.com/vllm-project/vllm/security/advisories/new). Reports will then be triaged by the [vulnerability management team](https://docs.vllm.ai/contributing/vulnerability_management/).
88

99
---
1010

docs/source/contributing/vulnerability_management.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,4 +32,12 @@ We prefer to keep all vulnerability-related communication on the security report
3232
on GitHub. However, if you need to contact the VMT directly for an urgent issue,
3333
you may contact the following individuals:
3434

35-
- ... TODO ...
35+
- Simon Mo - [email protected]
36+
- Russell Bryant - [email protected]
37+
38+
## Slack Discussion
39+
40+
You may use the `#security` channel in the [VLLM Slack](https://slack.vllm.ai)
41+
to discuss security-related topics. However, please do not disclose any
42+
vulnerabilities in this channel. If you need to report a vulnerability, please
43+
use the GitHub security advisory system or contact a VMT member privately.

0 commit comments

Comments
 (0)