From 0dba66d5e91cf57a9e7e65eca98f288e5794da1c Mon Sep 17 00:00:00 2001 From: Rafael Gonzaga Date: Tue, 28 Jun 2022 10:53:15 -0300 Subject: [PATCH] doc: include CVSS mention --- doc/contributing/security-release-process.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/doc/contributing/security-release-process.md b/doc/contributing/security-release-process.md index 4f19b0ce48d652..605821bad13b77 100644 --- a/doc/contributing/security-release-process.md +++ b/doc/contributing/security-release-process.md @@ -42,6 +42,8 @@ The current security stewards are documented in the main Node.js * [ ] PR release announcements in [private](https://github.com/nodejs-private/nodejs.org-private): * (Use previous PRs as templates. Don't forget to update the site banner and the date in the slug so that it will move to the top of the blog list.) + * (Consider using a [Vulnerability Score System](https://www.first.org/cvss/calculator/3.1) + to identify severity of each report) * [ ] pre-release: _**LINK TO PR**_ * [ ] post-release: _**LINK TO PR**_ * List vulnerabilities in order of descending severity