Skip to content

Commit

Permalink
Doc: add security policy file for CBDB (#110)
Browse files Browse the repository at this point in the history
Add new SECURITY.md file for cloudberry Database, which shows that
community how to report security issues, and rules on the security
issues. This version is 1.0. We need to update the policy along with our
community grows.
  • Loading branch information
tuhaihe authored Aug 2, 2023
1 parent 320bc30 commit 6fa1a9c
Showing 1 changed file with 49 additions and 0 deletions.
49 changes: 49 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
Thanks for helping make Cloudberry Database safe!

---

## Reporting Security Issues

To report a security issue, please email
[security@cloudberrydb.org](mailto:security@cloudberrydb.org). This
project follows a 90-day disclosure timeline. We will publish the
[security
advisories](https://github.com/cloudberrydb/cloudberrydb/security/advisories)
via GitHub.

You should receive a response within 2 weeks. If for some reason you
do not, please follow up via email to ensure we received your original
message.

Please include the requested information listed below (as much as you
can provide) to help us better understand the nature and scope of the
possible issue:

* Type of issue (e.g. buffer overflow, SQL injection, cross-site
scripting, etc.)
* Full paths of source file(s) related to the manifestation of the
issue
* The location of the affected source code (tag/branch/commit or
direct URL)
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the
issue

This information will help us triage your report more quickly.

## Do not

For better collaboration, we hope you:

- Do not file public issues on GitHub for security vulnerabilities.
- Do not report non-security-impacting bugs through this channel. If
you have any questions on using, development, please use [GitHub
Issues, Discussions or
Slack](https://github.com/cloudberrydb/cloudberrydb/issues/new/choose)
instead.

## Preferred Languages

We prefer all communications to be in English.

0 comments on commit 6fa1a9c

Please sign in to comment.