From 12cf986a94fec99f72e1d1c00d7672906809da36 Mon Sep 17 00:00:00 2001 From: Will Baldoumas <45316999+wbaldoumas@users.noreply.github.com> Date: Tue, 13 Feb 2024 13:51:52 -0800 Subject: [PATCH] Create SECURITY.md --- SECURITY.md | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..73410bb --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,40 @@ +# Security Policies and Procedures + +This document outlines security procedures and general policies for the +`coding-blog` project. + +- [Security Policies and Procedures](#security-policies-and-procedures) + - [Reporting a Bug](#reporting-a-bug) + - [Disclosure Policy](#disclosure-policy) + - [Comments on this Policy](#comments-on-this-policy) + +## Reporting a Bug + +The `coding-blog` team and community take all security bugs in +`coding-blog` seriously. Thank you for improving the security of +`coding-blog`. We appreciate your efforts and responsible disclosure and +will make every effort to acknowledge your contributions. + +Report security bugs by emailing `wbaldoumas.github@gmail.com`. + +The lead maintainer will acknowledge your email within 48 hours, and will send a +more detailed response within 48 hours indicating the next steps in handling +your report. After the initial reply to your report, the security team will +endeavor to keep you informed of the progress towards a fix and full +announcement, and may ask for additional information or guidance. + +## Disclosure Policy + +When the security team receives a security bug report, they will assign it to a +primary handler. This person will coordinate the fix and release process, +involving the following steps: + +- Confirm the problem and determine the affected versions. +- Audit code to find any potential similar problems. +- Prepare fixes for all releases still under maintenance. These fixes will be + released as quickly as possible. + +## Comments on this Policy + +If you have suggestions on how this process could be improved please submit a +pull request.