Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
urban-warrior committed Feb 11, 2023
1 parent e0b640e commit a8668be
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions SECURITY.md
@@ -1,13 +1,13 @@
# Security Policy

ImageMagick recommended practices **strongly** encourages you to configure a [security policy](https://imagemagick.org/script/security-policy.php) that suits your local environment.
It is strongly recommended to establish a [security policy](https://imagemagick.org/script/security-policy.php) suitable for your local environment before utilizing ImageMagick.

## Supported Versions

We encourage users to upgrade to the latest ImageMagick release to ensure that all known security vulnerabilities are addressed. On request, we can backport security fixes to other ImageMagick versions.

## Reporting a Vulnerability

Post any vulnerability as an [issue](https://github.com/ImageMagick/ImageMagick/issues). Or you can post privately to the ImageMagick development [team](https://imagemagick.org/script/contact.php). Most vulnerabilities are fixed within 48 hours.
Before you post a vulnerability, first determine if the vulnerability can be mitigated by the security policy. ImageMagick, by default, is open. Use the security policy to add constraints to meet the requirements of your local security governance. If you feel confident that the security policy does not address the vulnerability, post the vulnerability as an [issue](https://github.com/ImageMagick/ImageMagick/issues). Or you can post privately to the ImageMagick development [team](https://imagemagick.org/script/contact.php). Most vulnerabilities are fixed within 48 hours.

In addition, request a [CVE](https://www.cve.org/ResourcesSupport/ReportRequest). We rely on you to post CVE's so our development team can concentrate on delivering a robust security patch.

0 comments on commit a8668be

Please sign in to comment.