Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,7 @@ Configure the repository:
* Dependabot security updates
* Secret scanning
* Push protection
* Private vulnerability reporting

1. Go to repository Settings > Actions > General:

Expand Down
15 changes: 15 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Security Policy

## Supported Versions

Please do not use older minor versions, as these are not supported.
Only the latest minor version will receive patch releases.

## Reporting a Vulnerability

To report a security issue, please [privately report a security vulnerability](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability) through GitHub.
If you do not have a GitHub account, please email security@example.com with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue.
We will endeavour to respond within 3 working days of your email.

If an issue is confirmed as a vulnerability, we will open a Security Advisory.
This project follows a 30 day disclosure timeline.