Skip to content

Commit 758158a

Browse files
committed
add security.md
1 parent 564ec85 commit 758158a

File tree

1 file changed

+51
-0
lines changed

1 file changed

+51
-0
lines changed

SECURITY.md

Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
We support security fixes for the latest released version and the `master` branch.
6+
7+
| Version | Supported |
8+
| ------- | --------- |
9+
| Latest ||
10+
| Older ||
11+
12+
## Reporting a Vulnerability
13+
14+
If you believe you’ve found a security vulnerability, **please do not open a public GitHub issue**.
15+
16+
Instead, report it privately using one of the following:
17+
18+
### Preferred: GitHub Private Vulnerability Reporting
19+
- Go to: **Security****Advisories****Report a vulnerability**
20+
- Provide as much detail as possible (see “What to include” below).
21+
22+
### Alternative: Email
23+
- Email: **[email protected]**
24+
25+
## What to Include
26+
27+
Please include:
28+
- A clear description of the issue and potential impact
29+
- Steps to reproduce (proof-of-concept if available)
30+
- Affected versions/branches
31+
- Any suggested fix or mitigation (if you have one)
32+
33+
## Response Timeline
34+
35+
We aim to:
36+
- Acknowledge receipt within **3 business days**
37+
- Provide a status update within **7 business days**
38+
- Release a fix as soon as practical based on severity and complexity
39+
40+
## Coordinated Disclosure
41+
42+
We follow coordinated disclosure practices. Please allow reasonable time to investigate and remediate before any public disclosure.
43+
44+
## Security Updates
45+
46+
Security fixes may be released as:
47+
- Patch releases
48+
- Advisory notes (GitHub Security Advisory)
49+
- Changelog entries (when appropriate)
50+
51+
Thank you for helping keep this project and its users safe.

0 commit comments

Comments
 (0)