Skip to content

Commit 224ca8c

Browse files
authored
🔒️(security) create SECURITY.md for vulnerability reporting policy
Added a security policy document outlining vulnerability reporting and disclosure procedures.
1 parent 8e5bb50 commit 224ca8c

File tree

1 file changed

+23
-0
lines changed

1 file changed

+23
-0
lines changed

‎SECURITY.md‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
Security is very important to us.
6+
7+
If you have any issue regarding security, please disclose the information responsibly by emailing us at [email protected] and not by creating an issue on the repository.
8+
9+
We appreciate your effort to make Projects more secure.
10+
11+
## Vulnerability disclosure policy
12+
13+
Working with security issues in an open source project can be challenging, as we are required to disclose potential problems that could be exploited by attackers. With this in mind, our security fix policy is as follows:
14+
15+
1. The Maintainers team will handle the fix as usual (Pull Request,
16+
release).
17+
2. In the release notes, we will include the identification numbers from the
18+
GitHub Advisory Database (GHSA) and, if applicable, the Common Vulnerabilities
19+
and Exposures (CVE) identifier for the vulnerability.
20+
3. Once this grace period has passed, we will publish the vulnerability.
21+
22+
By adhering to this security policy, we aim to address security concerns
23+
effectively and responsibly in our open source software project.

0 commit comments

Comments
 (0)