Skip to content

Commit

Permalink
Create SECURITY.md
Browse files Browse the repository at this point in the history
GitHub now recommends that each repository contains a SECURITY.md file (per https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository)
  • Loading branch information
jmckenna committed Jul 30, 2021
1 parent 1eaf763 commit dab9991
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions SECURITY.md
@@ -0,0 +1,21 @@
# MapServer Security Policy

## Reporting a Vulnerability in MapServer

Security/vulnerability reports should not be submitted through GitHub tickets or the public mailing lists, but instead please send your report
to the email address: **mapserver-security nospam @ osgeo.org** (remove the blanks and ‘nospam’).

Please follow the general guidelines for bug
submissions, when describing the vulnerability (see https://mapserver.org/development/bugs.html).

## Supported Versions

The MapServer PSC (Project Steering Committee) will release patches for security vulnerabilities for the following versions:

| Version | Supported |
| ------- | ------------------ |
| 7.6.x | :white_check_mark: |
| 7.4.x | :white_check_mark: |
| 7.2.x | :white_check_mark: |
| 7.0.x | :white_check_mark: |
| < 7.0 | :x: |

2 comments on commit dab9991

@jmckenna
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sdlime sorry for adding this file directly (I was following the GitHub how-to steps to add). Can you review this? (versions supported) thanks!

@sdlime
Copy link
Member

@sdlime sdlime commented on dab9991 Jul 30, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should go to the -dev list for review. I'm not sure what folks thoughts are on supported versions - that's probably the key question.

Please sign in to comment.