Skip to content

Commit

Permalink
SECURITY.md: use private vulnerability reporting feature (#772)
Browse files Browse the repository at this point in the history
  • Loading branch information
tarcieri authored and ixti committed Feb 5, 2024
1 parent 03370c6 commit 81d281e
Showing 1 changed file with 13 additions and 1 deletion.
14 changes: 13 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,17 @@
# Security Policy

## Supported Versions

Security updates are applied only to the most recent release.

## Reporting a Vulnerability

Please report security issues to `bascule@gmail.com`
If you have discovered a security vulnerability in this project, please report
it privately. **Do not disclose it as a public issue.** This gives us time to
work with you to fix the issue before public exposure, reducing the chance that
the exploit will be used before a patch is released.

Please disclose it at [security advisory](https://github.com/httprb/http/security/advisories/new).

This project is maintained by a team of volunteers on a reasonable-effort basis.
As such, please give us at least 90 days to work on a fix before public exposure.

0 comments on commit 81d281e

Please sign in to comment.