Security policy for Dist::Zilla

This document explains how to report a security vulnerability in Dist::Zilla, and what to expect after you do.

Reporting a vulnerability

Please report security vulnerabilities privately, using GitHub's private vulnerability reporting. Go to https://github.com/rjbs/Dist-Zilla/security/advisories/new, or use the "Report a vulnerability" button on the repository's Security tab.

Please do not report security vulnerabilities through public GitHub issues, pull requests, or the mailing list.

Include enough detail to reproduce the problem. If you would like help triaging the issue, or believe it is being actively exploited, also copy your report to the CPAN Security Group (CPANSec) at cpan-security@security.metacpan.org.

What to expect

Not much! The maintainer checks bug reports against Dist::Zilla every week or so, but will acknowledge security reports when they're seen. Most bugs found in Dist::Zilla will not be security-related, and those will be kicked out into the public bug tracker ASAP.

If you have heard nothing after two weeks, send a reminder and copy CPANSec at the address above.

Please don't disclose the problem publicly until a fix has been released or a disclosure date has been agreed.