RFR: 8340954: Add SECURITY.md file

Andy Goryachev angorya at openjdk.org
Wed Sep 25 21:27:41 UTC 2024


On Wed, 25 Sep 2024 21:24:03 GMT, Kevin Rushforth <kcr at openjdk.org> wrote:

>> SECURITY.md line 3:
>> 
>>> 1: # JavaFX Vulnerabilities
>>> 2: 
>>> 3: Please follow the process outlined in the [OpenJDK Vulnerability Policy](https://openjdk.org/groups/vulnerability/report) to disclose vulnerabilities in JavaFX.
>> 
>> since FX is not technically a part of JDK, should it point to a separate (new) page instead of https://openjdk.org/groups/vulnerability/report ?
>
> No. JavaFX _is_ part of OpenJDK. It is irrelevant whether or not it happens to be bundled with the JDK.

+1

-------------

PR Review Comment: https://git.openjdk.org/jfx/pull/1578#discussion_r1776010566


More information about the openjfx-dev mailing list