Create security policy document

Fixes #3099
This commit is contained in:
Ben Darnell 2023-01-05 11:40:24 -05:00 committed by GitHub
parent e6db81650e
commit b92e517842
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 14 additions and 0 deletions

14
SECURITY.md Normal file
View File

@ -0,0 +1,14 @@
# Security Policy
## Supported Versions
In general, due to limited maintainer bandwidth, only the latest version of
Tornado is supported with patch releases. Exceptions may be made depending
on the severity of the bug and the feasibility of backporting a fix to
older releases.
## Reporting a Vulnerability
Tornado uses GitHub's security advisory functionality for private vulnerability
reports. To make a private report, use the "Report a vulnerability" button on
https://github.com/tornadoweb/tornado/security/advisories