Skip to content

Commit c9fa7cb

Browse files
committed
Add security policy document
1 parent a1ffd87 commit c9fa7cb

File tree

1 file changed

+37
-0
lines changed

1 file changed

+37
-0
lines changed

SECURITY.md

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
# Security Policies and Procedures
2+
3+
This document outlines security procedures and general policies for the
4+
`setup-powerpoint` action tool.
5+
6+
Security updates receive all v1.x releases.
7+
8+
## Reporting a Bug
9+
10+
The team and community take all security bugs seriously.
11+
Thank you for improving the security of `setup-powerpoint` action.
12+
We appreciate your efforts and responsible disclosure and
13+
will make every effort to acknowledge your contributions.
14+
15+
Report security bugs by emailing `[email protected]`.
16+
17+
The lead maintainer will acknowledge your email within 48 hours, and will send a
18+
more detailed response within 48 hours indicating the next steps in handling
19+
your report. After the initial reply to your report, the security team will
20+
endeavor to keep you informed of the progress towards a fix and full
21+
announcement, and may ask for additional information or guidance.
22+
23+
## Disclosure Policy
24+
25+
When the security team receives a security bug report, they will assign it to a
26+
primary handler. This person will coordinate the fix and release process,
27+
involving the following steps:
28+
29+
- Confirm the problem and determine the affected versions.
30+
- Audit code to find any potential similar problems.
31+
- Prepare fixes for all releases still under maintenance. These fixes will be
32+
released as quickly as possible.
33+
34+
## Comments on this Policy
35+
36+
If you have suggestions on how this process could be improved please submit an
37+
issue.

0 commit comments

Comments
 (0)