Commit 9039875a51
Unsigned
Layout: unified · split
SECURITY.md added +33
| @@ -0,0 +1,33 @@ | |||
| 1 | # Security Policy | ||
| 2 | |||
| 3 | ## Supported Versions | ||
| 4 | |||
| 5 | This section outlines which versions of the project are currently receiving | ||
| 6 | security updates. | ||
| 7 | |||
| 8 | | Version | Supported | | ||
| 9 | | ------- | ------------------ | | ||
| 10 | | 1.x | :white_check_mark: | | ||
| 11 | | < 1.0 | :x: | | ||
| 12 | |||
| 13 | ## Reporting a Vulnerability | ||
| 14 | |||
| 15 | If you discover a vulnerability, please follow the guidelines below to report | ||
| 16 | it: | ||
| 17 | |||
| 18 | 1. **Submission**: Send your vulnerability report to [security@cleberg.net]. | ||
| 19 | Please include a detailed description of the issue, steps to reproduce it, | ||
| 20 | and any relevant context. | ||
| 21 | |||
| 22 | 2. **Response Time**: We aim to acknowledge reports within **3 business days**. | ||
| 23 | You will receive updates on the status of your report throughout the process. | ||
| 24 | |||
| 25 | 3. **Acceptance Criteria**: If the vulnerability is confirmed, we will provide | ||
| 26 | you with an estimated timeline for resolution and keep you informed of any | ||
| 27 | updates until the issue is resolved. | ||
| 28 | |||
| 29 | 4. **Declined Reports**: If a reported vulnerability is deemed invalid or out of | ||
| 30 | scope, we will notify you of our decision and provide reasoning for the | ||
| 31 | decline. | ||
| 32 | |||
| 33 | Thank you for helping us improve the security of our project! | ||