Skip to content

Add SECURITY.md #5

@bilby91

Description

@bilby91

Standard short SECURITY.md for OSS projects: how to report a vulnerability privately (email or GitHub Security Advisory), what's in scope (engine + runtime/docker), what's out of scope (Docker daemon itself, the host system, user-supplied compose / Dockerfiles).

Should reference the project's expected response time and whether GitHub Security Advisories are accepted.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions