Skip to content

Commit 8ee49ba

Browse files
authored
docs: add security policy (#1037)
1 parent 31a15e7 commit 8ee49ba

File tree

1 file changed

+34
-0
lines changed

1 file changed

+34
-0
lines changed

SECURITY.md

+34
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# Security policy
2+
3+
## Release cycle
4+
5+
<!--
6+
The information under this header may not be strictly accurate for all apps and libraries.
7+
Review the wording carefully and only copy it if the support offered makes sense. If it
8+
seems wrong, speak with Canonical Security Engineering about refining a version for
9+
your application.
10+
-->
11+
12+
Canonical tracks and responds to vulnerabilities in:
13+
14+
- The most recent patch version of Craft Parts.
15+
- Any version of Craft Parts that's included in a current release of a Canonical
16+
product.
17+
18+
## Reporting a vulnerability
19+
20+
<!---
21+
Replace the first link in this section with your repository's advisories board. See
22+
GitHub's documentation for enabling the security advisory tab on a repository:
23+
https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository
24+
-->
25+
26+
To report a security issue, file a [Private Security Report] with a description of the
27+
issue, the steps you took to create the issue, affected versions, and, if known,
28+
mitigations for the issue.
29+
30+
The [Ubuntu Security disclosure and embargo policy] contains more information about
31+
what you can expect when you contact us and what we expect from you.
32+
33+
[Private Security Report]: https://github.com/canonical/craft-parts/security/advisories/new
34+
[Ubuntu Security disclosure and embargo policy]: https://ubuntu.com/security/disclosure-policy

0 commit comments

Comments
 (0)