Skip to content

Commit 0372fab

Browse files
Update _articles/security-best-practices-for-your-project.md
Co-authored-by: Xavier RENE-CORAIL <xcorail@github.com>
1 parent c4edccf commit 0372fab

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

_articles/security-best-practices-for-your-project.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ Your process doesn't have to be complex. At minimum, define:
119119
* What steps you take to prepare a fix and coordinate disclosure
120120
* How you notify affected users, contributors, or downstream consumers
121121

122-
Coordinated disclosure works best when there's a clear plan. Publishing this (or linking to it) in your `SECURITY.md` file can help set expectations and build trust.
122+
An active incident, if not well managed, can erode trust in your project from your users. Publishing this (or linking to it) in your `SECURITY.md` file can help set expectations and build trust.
123123

124124
For inspiration, the [Express.js Security WG](https://github.com/expressjs/security-wg/blob/main/docs/incident_response_plan.md) provides a simple but effective example of an open source incident response plan.
125125

0 commit comments

Comments
 (0)