icon-project/community

Add stuff about the security response committee.

Opened this issue · 0 comments

TODO: Add stuff about the security response committee.

# Security Release Process

This document defines the ICON Foundation's security vulnerability reporting and fix release processes.

## Security advisories

{/* 
  TODO: Add stuff about the security response committee.
  assignees: han-so1omon
*/}

## Postmortem

A postmortem should be published within 3 business days after the vulnerability fix is released. The postmortem should follow  [Google's SRE postmortem best practices](https://landing.google.com/sre/book/chapters/postmortem-culture.html).