Skip to content

Commit de415f1

Browse files
authored
Add Tidelift security notice
1 parent c4f2c8c commit de415f1

1 file changed

Lines changed: 34 additions & 0 deletions

File tree

‎SECURITY.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
Only the latest version is supported, unless a maintained branch exists for an
6+
older major (e.g. `2.x.x`).
7+
8+
That said, if an unsupported version still has significant download numbers and
9+
you believe a vulnerability could have real impact, please report it anyway —
10+
it will be considered.
11+
12+
## Reporting a Vulnerability
13+
14+
To report a security vulnerability, please use the
15+
[Tidelift security contact](https://tidelift.com/security).
16+
Tidelift will coordinate the fix and disclosure.
17+
18+
When reporting, please include as much detail as possible:
19+
20+
- A description of the vulnerability and its impact
21+
- Steps to reproduce (a minimal reproduction is ideal)
22+
- Affected version(s)
23+
- Any suggested fix or mitigation, if you have one
24+
25+
## What to Expect
26+
27+
- Acknowledgement of your report within a reasonable delay.
28+
- Confirmation of the issue and an assessment of its severity.
29+
- A fix released as soon as reasonably possible, with credit to the reporter
30+
(unless you'd rather stay anonymous).
31+
32+
This is an open source project maintained on a best-effort basis, so timelines
33+
may vary — thanks for your understanding, and for helping keep the ecosystem
34+
safe.

0 commit comments

Comments
 (0)