diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..1955f0a --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,30 @@ +# Security Policy + +This policy applies to all [Development Seed](https://github.com/developmentseed) repositories that do not define their own `SECURITY.md`. + +## Reporting a Vulnerability + +**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.** + +Instead, report them privately via GitHub's [private vulnerability reporting](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability): open the affected repository's **Security** tab and click **Report a vulnerability**. + +If that button is not available for a repository, open an issue asking the maintainers for a private contact, **without including any details of the vulnerability**. + +Please include as much of the following as you can: + +- A description of the issue and its impact +- Steps to reproduce, ideally with a minimal example +- Affected version(s) and relevant configuration +- Any suggested fix or mitigation + +## What to Expect + +- We aim to acknowledge reports within **5 business days**. +- We will keep you informed as we investigate and work on a fix. +- Once a fix is released, we will publish a GitHub Security Advisory and, where appropriate, request a CVE. Reporters are credited unless they prefer to remain anonymous. + +Please give us a reasonable amount of time to address the issue before any public disclosure. + +## Supported Versions + +Unless a repository states otherwise, security fixes are applied to the latest release only.