Skip to content

Commit

Permalink
docs: add security policy to repo root
Browse files Browse the repository at this point in the history
Signed-off-by: Xander Grzywinski <xandergrzyw@gmail.com>
  • Loading branch information
salaxander committed May 9, 2024
1 parent 898061d commit 4174e2b
Showing 1 changed file with 17 additions and 0 deletions.
17 changes: 17 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Reporting Security Issues

To report a security issue or vulnerability in Zarf, please use the confidential GitHub Security Advisory ["Report a Vulnerability"](https://github.com/defenseunicorns/zarf/security/advisories) tab. The Zarf team will send a response indicating the next steps in handling your report. After the initial reply to your report, the team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.

### When Should I Report a Vulnerability?

* You found a vulnerability in the Zarf code.
* You found a vulnerability in one of the Zarf dependencies that affects the project that has not been patched yet.

### When Should I NOT Report a Vulnerability?

* You found a bug or malfunction in the Zarf code (not security related).
* You want to add a feature to Zarf.

## Contacting Us

To discuss security related issues, please email the maintainers at zarf-dev-private@googlegroups.com.

0 comments on commit 4174e2b

Please sign in to comment.