Add security policy (#31)

This commit is contained in:
Pavel Popov 2022-11-24 19:31:50 +07:00 committed by GitHub
parent 02ed5a5f3e
commit 79a8b40bfc
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

13
SECURITY.md Normal file
View File

@ -0,0 +1,13 @@
# Security Policy
If you think you have identified a security related issue with a repository, please report it immediately to the lead maintainer at <a href="mailto:security@vality.dev?subject=SECURITY REPO-NAME-HERE">security@vality.dev</a>. If you are not sure, dont worry. Better safe than sorry just send an email.
Do not open issues related to any security concerns publicly. Please do not include anyone else on the disclosure email. Preferably only one point of contact for replies.
When reporting an issue, include as much information as possible. Just tell us what you found, how to reproduce it, and any concerns you have about it. We will respond as soon as possible and follow up with any missing information.
## Disclosure Policy
Once an issue has been confirmed, we will work to resolve it.
If you have a suggestion for a patch; Coordinate with the lead maintainer for when to publicly post an issue and pull request. Giving you credit for your effort.