Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

#84 | Add SECURITY.md file for reporting vulnerabilities #140

Merged
merged 3 commits into from
Sep 23, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# Security Policy

## Reporting a Vulnerability

If you discover a security vulnerability in this project, we appreciate your responsible disclosure. To report a vulnerability, please follow these steps:

1. **Do Not Disclose Publicly**
Do not open a public issue regarding the vulnerability. We ask that you keep the information confidential until we can address the issue and notify our users.

2. **Send a Report**
You can report any vulnerabilities via email to the following contact:

**Security Team Contact**: [[email protected]](mailto:[email protected])

3. **Include the Following Information**
- Detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any possible mitigations you can suggest

4. **Response Time**
We will respond to your report within 48 hours. After the initial assessment, we will provide you with a detailed plan to address the issue, including the timeline for a fix.

5. **Acknowledgement**
Once the vulnerability is resolved, we will give you credit for the responsible disclosure in our release notes, unless you prefer to remain anonymous.

## Security Updates

We continuously monitor and update dependencies for security patches. Please ensure you are using the latest version of our software to stay protected.

Loading