Skip to content

Commit 7eaa45d

Browse files
committed
Added security policy
1 parent 80dafb4 commit 7eaa45d

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed

.github/SECURITY.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
If there are any vulnerabilities in **Slevomat Coding Standard**, don't hesitate to _report them_.
6+
7+
1. Use the [private email address](https://www.slevomat.cz/.well-known/security.txt).
8+
2. Describe the vulnerability.
9+
10+
If you have a fix, that is most welcome -- please attach or summarize it in your message!
11+
12+
3. We will evaluate the vulnerability and, if necessary, release a fix or mitigating steps to address it. We will contact you to let you know the outcome, and will credit you in the report.
13+
14+
Please **do not disclose the vulnerability publicly** until a fix is released!
15+
16+
4. Once we have either a) published a fix, or b) declined to address the vulnerability for whatever reason, you are free to publicly disclose it.
17+
18+
## Tidelift subscribers
19+
20+
If you're a [Tidelift](https://tidelift.com/) subscriber, please use this route instead:
21+
22+
To report a security vulnerability, please use the
23+
[Tidelift security contact](https://tidelift.com/security).
24+
Tidelift will coordinate the fix and disclosure.

0 commit comments

Comments
 (0)