Create SECURITY.md

This commit is contained in:
Max Bachmann 2022-09-27 04:23:18 +02:00 committed by GitHub
parent cfe09cff18
commit 455e08c2cc
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 19 additions and 0 deletions

19
SECURITY.md Normal file
View File

@ -0,0 +1,19 @@
## Reporting Security Issues
If you believe you have found a security vulnerability in the project, please report it to us through coordinated disclosure.
**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.**
Instead, please send an email to security@maxbachmann.de or report it via https://tidelift.com/security.
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
* The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting)
* Full paths of source file(s) related to the manifestation of the issue
* The location of the affected source code (tag/branch/commit or direct URL)
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the issue
This information will help us triage your report more quickly.