From 869c729fc833d13ba02d90af2323d2d2055d6e8d Mon Sep 17 00:00:00 2001 From: Nico Rikken Date: Thu, 5 Jun 2025 09:35:19 +0200 Subject: [PATCH 1/2] Create SECURITY.md Add standard Alliander SECURITY.md Signed-off-by: Nico Rikken --- SECURITY.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..ad83adb --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ + + +# Security + +At Alliander, we consider the security of our systems and software a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present. + +If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems. + +## Report a security issue + +Use the contact details on the [Alliander.com Vulnerability Reporting page](https://www.alliander.com/en/coordinated-vulnerability-disclosure/). + +Please describe clearly how the issue can be reproduced, so we can fix it quickly. Typically, the IP address or URL of the affected system and a description of the vulnerability are sufficient. We may contact you if we need more information about a complex vulnerability. + +## Thanks + +We don't have a bug bounty program, but we're grateful for all the reports we get. We offer an Alliander Security hoodie as a reward for significant security problems. From 68c14b2a943c87c29902f9814926f621394349f2 Mon Sep 17 00:00:00 2001 From: Nico Rikken Date: Fri, 6 Jun 2025 11:00:39 +0200 Subject: [PATCH 2/2] remove trailing whitespace of security.md Signed-off-by: Nico Rikken --- SECURITY.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index ad83adb..f1a8c68 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,20 +1,20 @@ # Security -At Alliander, we consider the security of our systems and software a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present. +At Alliander, we consider the security of our systems and software a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present. -If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems. +If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems. ## Report a security issue Use the contact details on the [Alliander.com Vulnerability Reporting page](https://www.alliander.com/en/coordinated-vulnerability-disclosure/). -Please describe clearly how the issue can be reproduced, so we can fix it quickly. Typically, the IP address or URL of the affected system and a description of the vulnerability are sufficient. We may contact you if we need more information about a complex vulnerability. +Please describe clearly how the issue can be reproduced, so we can fix it quickly. Typically, the IP address or URL of the affected system and a description of the vulnerability are sufficient. We may contact you if we need more information about a complex vulnerability. ## Thanks