diff --git a/SECURITY.md b/SECURITY.md index 9afd9af..3a2a1ea 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,5 +1,13 @@ -# Reporting Security Issues +# Security Policy -To report a security issue, please email [oss@kommit.co](mailto:oss@kommit.co) with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. +## Reporting Security Issues + +To report a security issue, you can either: +- Privately report a vulnerability through repository's Security tab by clicking "Report a vulnerability". +- Email us at [oss@kommit.co](mailto:oss@kommit.co). + +Please, make sure to provide a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. + +## Responsible Disclosure If the issue is confirmed as a vulnerability, we will open a Security Advisory and acknowledge your contributions as part of it.