The PHP Foundation Ecosystem Security Team published a maintainer guide for handling vulnerability reports, covering private triage, safe reproduction, scope decisions, coordinated disclosure, CVEs and advisories, and places where PHP project maintainers can ask the Alpha-Omega-backed team for help.
So You Received a Security Report. Now What?
The PHP Foundation Ecosystem Security Team published a maintainer guide for handling vulnerability reports, covering private triage, safe reproduction, scope decisions, coordinated disclosure, CVEs and advisories, and places where PHP project maintainers can ask the Alpha-Omega-backed team for help.
Source: Thephp