@@ -118,7 +118,7 @@ Vulnerabilities and incidents may be reported or discovered through:
118118 - Whether they intend to publish their own advisory, and if so, their preferred timeline
119119 - Thank them explicitly — reporters do the project a favour by disclosing privately.
1201202 . Reproduce the issue. If the report is invalid, close it and notify the reporter.
121- 3 . Assign a severity level ([ §5 Severity Classification] ( #5-severity-classification ) ).
121+ 3 . Assign a severity level ([ Section 5: Severity Classification] ( #5-severity-classification ) ).
1221224 . If the GitHub Security Advisory was not created by the reporter, create one now and keep
123123 it ** private** until the fix is released. Add the reporter as a collaborator if they wish
124124 to be involved.
@@ -183,8 +183,8 @@ If a security patch introduces a critical regression after release:
183183 that the release has been yanked.
1841843 . If the previous (vulnerable) version was also yanked, ** un-yank it temporarily** so users
185185 have a functional fallback while the corrected release is prepared.
186- 4 . Prepare a corrected point release (incrementing the patch version), repeating § 7.2–§ 7.3.
187- 5 . Document the regression in the post-incident review (§ 9).
186+ 4 . Prepare a corrected point release (incrementing the patch version), repeating sections 7.2–7.3.
187+ 5 . Document the regression in the post-incident review (Section 9).
188188
189189### 7.6 Supply-Chain / Infrastructure Compromise
190190
@@ -365,9 +365,9 @@ When a CVE is published for a bundled C library:
365365This document is a living record. It should be kept current so it is useful when an
366366incident actually occurs.
367367
368- - ** Quarterly review** — revisit during the § 1.3 readiness review at each quarterly release.
368+ - ** Quarterly review** — revisit during the Section 1.3 readiness review at each quarterly release.
369369- ** Post-incident update** — if the response process revealed gaps or needed improvisation,
370- update this document before the post-incident review is closed (§ 9).
370+ update this document before the post-incident review is closed (Section 9).
371371- ** Ownership** — changes are approved by the Core Team and recorded in Git history.
372372 Substantive changes should be noted in the PR description so they are easy to find later.
373373
0 commit comments