Skip to content

Commit 60dcb74

Browse files
authored
Create SECURITY.md
1 parent dd51f56 commit 60dcb74

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

SECURITY.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
If there are any vulnerabilities in **PHPStan**, don't hesitate to _report them_.
6+
7+
1. Use the [private email address](mailto:[email protected]).
8+
2. Describe the vulnerability.
9+
10+
If you have a fix, that is most welcome -- please attach or summarize it in your message!
11+
12+
3. We will evaluate the vulnerability and, if necessary, release a fix or mitigating steps to address it. We will contact you to let you know the outcome, and will credit you in the report.
13+
14+
Please **do not disclose the vulnerability publicly** until a fix is released!
15+
16+
4. Once we have either a) published a fix, or b) declined to address the vulnerability for whatever reason, you are free to publicly disclose it.

0 commit comments

Comments
 (0)