Skip to content

Commit

Permalink
Docs: add security policy
Browse files Browse the repository at this point in the history
- Latest version is supported
- Report vulnerabilities via e-mail
  • Loading branch information
lovell committed Apr 20, 2023
1 parent d08baa2 commit a39f959
Show file tree
Hide file tree
Showing 2 changed files with 18 additions and 2 deletions.
18 changes: 18 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Security Policy

## Supported Versions

The latest version of `sharp` as published to npm
and reported by `npm view sharp dist-tags.latest`
is supported with security updates.

## Reporting a Vulnerability

Please use
[e-mail](https://github.com/lovell/sharp/blob/main/package.json#L5)
to report a vulnerability.

You can expect a response within 48 hours
if you are a human reporting a genuine issue.

Thank you in advance.
2 changes: 0 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,8 +98,6 @@ readableStream
A [guide for contributors](https://github.com/lovell/sharp/blob/main/.github/CONTRIBUTING.md)
covers reporting bugs, requesting features and submitting code changes.

[![Node-API v5](https://img.shields.io/badge/Node--API-v5-green.svg)](https://nodejs.org/dist/latest/docs/api/n-api.html#n_api_n_api_version_matrix)

## Licensing

Copyright 2013 Lovell Fuller and others.
Expand Down

0 comments on commit a39f959

Please sign in to comment.