Skip to content

Commit 76d249e

Browse files
authored
add SECURITY.md (#31)
1 parent 2f1ffd6 commit 76d249e

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

SECURITY.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
If you think that you have found a security issue,
6+
don’t use the bug tracker and don’t publish it publicly.
7+
Instead, all security issues must be reported via a private vulnerability report.
8+
9+
Please follow the [instructions](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability) to submit a private report.
10+
11+
12+
## Resolving Process
13+
Every submitted security issue is handled with top priority by following these steps:
14+
15+
1. Confirm the vulnerability
16+
2. Determine the severity
17+
3. Contact reporter
18+
4. Work on a patch
19+
5. Get a CVE identification number (may be done by the reporter or a security service provider)
20+
6. Patch reviewing
21+
7. Tagging a new release for supported versions
22+
8. Publish security announcement

0 commit comments

Comments
 (0)