Skip to content

Commit 4c3c946

Browse files
janderssonseorhun
andauthored
docs(security): extend security policy (#1142)
* docs(security): extend security policy Signed-off-by: Josef Andersson <janderssonse@proton.me> * style: tweak security reporting docs --------- Signed-off-by: Josef Andersson <janderssonse@proton.me> Co-authored-by: Orhun Parmaksız <orhunparmaksiz@gmail.com>
1 parent 8c499c6 commit 4c3c946

1 file changed

Lines changed: 29 additions & 3 deletions

File tree

SECURITY.md

Lines changed: 29 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
1-
# Security Policy
1+
# Security
2+
3+
If you wish to report a security vulnerability privately, we appreciate your diligence. Please follow the guidelines below to submit your report.
24

35
## Supported Versions
46

@@ -11,6 +13,30 @@ The following versions are supported with security updates:
1113
| 1.0.x | :x: |
1214
| < 0.1.0 | :x: |
1315

14-
## Reporting a Vulnerability
16+
## Reporting
17+
18+
To report a security vulnerability, please provide the following information:
19+
20+
1. **PUBLIC**
21+
22+
- Indicate whether this vulnerability has already been publicly discussed or disclosed.
23+
- If so, provide relevant links.
24+
25+
2. **DESCRIPTION**
26+
- Provide a detailed description of the security vulnerability.
27+
- Include as much information as possible to help us understand and address the issue.
28+
29+
Send this information, along with any additional relevant details, to <orhunparmaksiz@gmail.com>.
30+
31+
## Confidentiality
32+
33+
We kindly ask you to keep the report confidential until a public announcement is made.
34+
35+
## Notes
36+
37+
- Vulnerabilities will be handled on a best-effort basis.
38+
- You may request an advance copy of the patched release, but we cannot guarantee early access before the public release.
39+
- You will be notified via email simultaneously with the public announcement.
40+
- We will respond within a few weeks to confirm whether your report has been accepted or rejected.
1541

16-
Please use the [GitHub Security Advisories](https://github.com/orhun/git-cliff/security/advisories/new) feature to report vulnerabilities.
42+
Thank you for helping to improve the security of **git-cliff**! ⛰️

0 commit comments

Comments
 (0)