Skip to content

Commit

Permalink
[Docs] Add SECURITY.md
Browse files Browse the repository at this point in the history
The paragraph "The Gramine team will send a response..." is based on
https://github.com/electron/electron/blob/28-x-y/SECURITY.md.

Signed-off-by: Dmitrii Kuvaiskii <dmitrii.kuvaiskii@intel.com>
  • Loading branch information
dimakuv committed Nov 27, 2023
1 parent 85d296c commit e053030
Show file tree
Hide file tree
Showing 3 changed files with 18 additions and 5 deletions.
4 changes: 0 additions & 4 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,3 @@ contact_links:
- name: 💬 I need help with Gramine usage
url: https://github.com/gramineproject/gramine/discussions/categories/general
about: Open a discussion thread
- name: 🔒 Report a security vulnerability
# GitHub doesn't seem to accept `mailto:` URLs here :/
url: https://gramine.readthedocs.io/en/latest/devel/contributing.html#reporting-security-vulnerabilities
about: Write an email to security@gramineproject.io
3 changes: 2 additions & 1 deletion README.rst
Original file line number Diff line number Diff line change
Expand Up @@ -90,4 +90,5 @@ If you prefer emails, please send them to users@gramineproject.io
Reporting security issues
=========================

Please report security issues to security@gramineproject.io.
Please report security issues to security@gramineproject.io. See also our
`security policy <SECURITY.md>`__.
16 changes: 16 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Reporting Security Issues

Please report security issues to security@gramineproject.io.

Please note that the Gramine team analyzes security bugs only on the current
`master` branch. This implies that you must reproduce the bug on master before
reporting.

The Gramine team will send a response indicating the next steps in handling your
report. After the initial reply to your report, the security team will keep you
informed of the progress towards a fix and full announcement, and may ask for
additional information or guidance.

If the bug report is correct, we will acknowledge your contributions by
specifying your name in the commit message. Please provide the preferred
name/nick to put there.

0 comments on commit e053030

Please sign in to comment.