From 4b711d2e2c4c161a0631139d1ec7386b85b76dfa Mon Sep 17 00:00:00 2001 From: Mark Fussell Date: Fri, 21 Jun 2024 21:02:44 -0700 Subject: [PATCH] Update daprdocs/content/en/operations/support/support-security-issues.md Co-authored-by: Hannah Hunter <94493363+hhunter-ms@users.noreply.github.com> Signed-off-by: Mark Fussell --- .../content/en/operations/support/support-security-issues.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/daprdocs/content/en/operations/support/support-security-issues.md b/daprdocs/content/en/operations/support/support-security-issues.md index 22e3f7165..8929d96af 100644 --- a/daprdocs/content/en/operations/support/support-security-issues.md +++ b/daprdocs/content/en/operations/support/support-security-issues.md @@ -36,7 +36,7 @@ can be useful! We tend to find, however, that when these reports are sent to our mailing list they almost always represent false positives, since these tools tend to check for the presence of a library without considering how the library is used in context. -If we receive a report which seems to simply be a vulnerability list from a scanner we +If we receive a report which seems to simply be a vulnerability list from a scanner, we reserve the right to ignore it. This applies especially when tools produce vulnerability identifiers which are not publicly