manage.get.gov/.github/SECURITY.md
Cameron Dixon 7563cff1c0
revise SECURITY.md
Revise and reformat, move VDP link lower in the doc
2023-05-30 11:30:44 -04:00

971 B

  • If you've found a security or privacy issue on the .gov top-level domain infrastructure, submit it to our vulnerabilty disclosure form or email dotgov@cisa.dhs.gov.
  • If you see a security or privacy issue on an individual .gov domain, check current-full.csv or Whois (same data) to check whether the domain has a security contact to report your finding directly. You are welcome to Cc dotgov@cisa.dhs.gov on the email.
    • If you are unable to find a contact or receive no response from the security contact, email dotgov@cisa.dhs.gov.

Note that most federal (executive branch) agencies maintain a vulnerability disclosure policy.