11<!--
2- $PostgreSQL: pgsql/doc/src/sgml/problems.sgml,v 2.19 2004/08/24 00:06:50 neilc Exp $
2+ $PostgreSQL: pgsql/doc/src/sgml/problems.sgml,v 2.20 2005/01/30 21:31:48 tgl Exp $
33-->
44
55<sect1 id="bug-reporting">
@@ -309,6 +309,13 @@ $PostgreSQL: pgsql/doc/src/sgml/problems.sgml,v 2.19 2004/08/24 00:06:50 neilc E
309309 <email>pgsql-bugs@postgresql.org</email> mailing list.
310310 </para>
311311
312+ <para>
313+ If your bug report has security implications and you'd prefer that it
314+ not become immediately visible in public archives, don't send it to
315+ <literal>pgsql-bugs</literal>. Security issues can be
316+ reported privately to <email>security@postgresql.org</email>.
317+ </para>
318+
312319 <para>
313320 Do not send bug reports to any of the user mailing lists, such as
314321 <email>pgsql-sql@postgresql.org</email> or
@@ -324,8 +331,8 @@ $PostgreSQL: pgsql/doc/src/sgml/problems.sgml,v 2.19 2004/08/24 00:06:50 neilc E
324331 This list is for discussing the
325332 development of <productname>PostgreSQL</productname>, and it would be nice
326333 if we could keep the bug reports separate. We might choose to take up a
327- discussion
328- about your bug report on <literal>pgsql-hackers</literal>, if the problem needs more review.
334+ discussion about your bug report on <literal>pgsql-hackers</literal>,
335+ if the problem needs more review.
329336 </para>
330337
331338 <para>