Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create SECURITY.md #1383

Merged
merged 1 commit into from
Oct 7, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Security Policy

## Supported Versions

This section outlines the versions of the project currently receiving security updates.

| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
| 5.0.x | :x: |
| 4.0.x | :white_check_mark: |
| < 4.0 | :x: |

## Reporting a Vulnerability

If you discover a potential security vulnerability, please report it to us promptly. Here’s how you can do so:

1. **Submit a Report:** Send an email to daskushal980@gmail.com with a detailed description of the vulnerability, including any relevant steps to reproduce the issue. Please include your contact information so we can follow up if needed.

2. **Response Time:** We aim to acknowledge all reports within **48 hours**. Our team will review the details you provide and assess the severity of the vulnerability.

3. **Updates:** Once a vulnerability is accepted for investigation, we will provide updates on our progress every **7 days**. If a vulnerability is declined, we will inform you of the reasons for our decision.

4. **Resolution Process:** If your reported vulnerability is accepted, we will work to address it as quickly as possible. Once a fix is implemented, we will communicate with you before any public disclosure to ensure you are informed.

5. **Responsible Disclosure:** We appreciate your cooperation in following responsible disclosure practices. Please do not disclose the vulnerability publicly until we have released a fix and communicated it to you.

Thank you for helping us keep our project secure!
Loading