Skip to content

Commit

Permalink
⚙️ internal(none): security.md (#2408)
Browse files Browse the repository at this point in the history
add security.md

## Type of change

**NONE: internal change**
  • Loading branch information
kellymears committed Aug 15, 2023
1 parent 9bd7129 commit 6cbd959
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Reporting Security Issues

If you believe you have found a security vulnerability in bud.js, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.

While we take security very seriously it is important to remember that nearly all bud.js dependencies are run in local developer environments only, and even more bud.js dependencies are only used within the context of this repository. In the context of a build tool, many "vulenrabilities" are safe to ignore. Runtime vulnerabilities will always be taken very seriously and handled with urgency.

Check out [npm audit: Broken by Design by Dan Abramov](https://overreacted.io/npm-audit-broken-by-design/) if you're interested in our thinking around the severity of non runtime security issues.

0 comments on commit 6cbd959

Please sign in to comment.