blob: ac8d16b93634f4779412c529502d58054a4bf85e [file] [view]
# Security Policy
## Reporting a Vulnerability
`apache/brpc` follows the [Apache Software Foundation security process](https://www.apache.org/security/). Please report suspected
vulnerabilities privately to `security@apache.org`; do not open public
GitHub issues or pull requests for security reports.
## Threat Model
What the project treats as in scope and out of scope, the security
properties it provides and disclaims, the adversary model, and how
findings are triaged are documented in [THREAT_MODEL.md](./THREAT_MODEL.md).