-
Notifications
You must be signed in to change notification settings - Fork 31
Expand file tree
/
Copy pathSECURITY.md.template
More file actions
74 lines (49 loc) · 2.08 KB
/
Copy pathSECURITY.md.template
File metadata and controls
74 lines (49 loc) · 2.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
# Security Policy Template
This is a template SECURITY.md file you can add to your repository after enabling security features.
---
# Security Policy
## Reporting a Vulnerability
We take the security of this project seriously. If you discover a security vulnerability, please report it responsibly.
### How to Report
**For security vulnerabilities, please DO NOT open a public issue.**
Instead, please report security vulnerabilities through one of the following methods:
1. **Private Vulnerability Reporting** (Recommended)
- Go to the [Security Advisories](../../security/advisories) page
- Click "Report a vulnerability"
- Provide detailed information about the vulnerability
2. **Email**
- Send details to: [[email protected]]
- Include "SECURITY" in the subject line
### What to Include
Please include the following information in your report:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if you have one)
### Response Timeline
- We will acknowledge receipt of your report within 48 hours
- We will provide a detailed response within 7 days
- We will keep you informed of our progress
- We will credit you in the fix announcement (unless you prefer to remain anonymous)
## Supported Versions
| Version | Supported |
| ------- | ------------------ |
| latest | ✅ Yes |
| older | ❌ No |
## Security Features
This repository has the following security features enabled:
- ✅ Branch Protection
- ✅ Private Vulnerability Reporting
- ✅ Secret Scanning with Push Protection
- ✅ Dependabot Security Updates
- ✅ Code Scanning (CodeQL) including Actions workflow security
## Security Best Practices
When contributing to this project:
- Never commit secrets (API keys, passwords, tokens)
- Keep dependencies up to date
- Follow secure coding practices
- Review Dependabot alerts and PRs promptly
## Questions?
If you have questions about this security policy, please open a discussion or contact the maintainers.
---
Thank you for helping keep this project secure! 🔒