Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 9 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,15 +4,20 @@ As a U.S. Government agency, the General Services Administration (GSA) takes
seriously our responsibility to protect the public's information, including
financial and personal information, from unwarranted disclosure.

Software developed by the U.S. General Services Administration (GSA)
is subject to the [GSA Vulnerability Disclosure Policy <gsa.gov/vulnerability-disclosure-policy>](gsa.gov/vulnerability-disclosure-policy).
## Reporting a Vulnerability

Services operated by the U.S. General Services Administration (GSA)
are covered by the **GSA Vulnerability Disclosure Program (VDP)**.

See the [GSA Vulnerability Disclosure Policy](https://www.gsa.gov/vulnerability-disclosure-policy)
at <https://www.gsa.gov/vulnerability-disclosure-policy> for details including:

Please consult our policy for:
* How to submit a report if you believe you have discovered a vulnerability.
* Bug bounty scope.
* GSA's coordinated disclosure policy.
* Information on how you may conduct security research on GSA developed
software and systems.
* Important legal and policy guidelines.
* Important legal and policy guidance.

## Supported Versions

Expand Down
Loading