Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
update content
  • Loading branch information
epreston committed Nov 3, 2023
1 parent e9a16cd commit 1ed9935
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,12 @@

## Supported Versions

This is an open source project that is provided as-is without warranty or liability.
This is an open source project that is provided as-is without warranty or liability. As such, we can make no support commitment. The maintainers will do the best they can to address any report promptly and responsibly.

As such no supportability commitment. The maintainers will do the best they can to address any report promptly and responsibly.
While the discovery of new vulnerabilities is rare, we also recommend always using the latest versions of this library and its official companion libraries to ensure your application remains as secure as possible.

## Reporting a Vulnerability

Please use the "Private vulnerability reporting" feature in the GitHub repository (under the "Security" tab).

Please note that we do not consider XSS via asset loading methods a valid attack vector, because it can only happen if the user intentionally uses untrusted content as an asset. This is similar to knowingly pasting untrusted scripts into a browser console. We explicitly warn users against using untrusted content as a resource in their application.

0 comments on commit 1ed9935

Please sign in to comment.