Skip to content

Commit e53da9a

Browse files
authored
Create SECURITY.md
1 parent 87dfa37 commit e53da9a

File tree

1 file changed

+36
-0
lines changed

1 file changed

+36
-0
lines changed

SECURITY.md

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
2+
# Security Policy
3+
4+
## Reporting Security Issues
5+
6+
At Spirit Solutions, we take security seriously. We welcome and appreciate responsible disclosure of any security vulnerabilities you may find in our "secure-web" npm package.
7+
8+
To report a security vulnerability, please email us directly at [[email protected]](mailto:[email protected]). We will acknowledge receipt of your vulnerability report and work to address any issues promptly.
9+
10+
## Responsible Disclosure Guidelines
11+
12+
When reporting vulnerabilities, please provide the following information:
13+
14+
- Description of the vulnerability.
15+
- Steps to reproduce the vulnerability.
16+
- Potential impact of the vulnerability.
17+
- Your name and contact information (optional).
18+
19+
## Response Timeline
20+
21+
We strive to respond to security vulnerability reports in a timely manner. Our typical response timeline is as follows:
22+
23+
- **Acknowledgement**: We will acknowledge receipt of your report within 48 hours.
24+
- **Investigation**: Our team will investigate the reported vulnerability to verify its legitimacy and impact.
25+
- **Resolution**: Once validated, we will work to address the vulnerability and provide updates on our progress.
26+
- **Public Disclosure**: We will coordinate with you to publicly disclose the vulnerability once it has been resolved, ensuring responsible disclosure practices are followed.
27+
28+
## Scope
29+
30+
This security policy applies to all aspects of the "secure-web" npm package developed and maintained by Spirit Solutions, including the codebase, documentation, and associated assets.
31+
32+
## Help Us Keep "secure-web" Secure
33+
34+
We appreciate your help in keeping "secure-web" secure. If you have any questions or concerns about our security policy or practices, please don't hesitate to contact us at [[email protected]](mailto:[email protected]).
35+
36+
---

0 commit comments

Comments
 (0)