diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..c956d328 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,26 @@ +# Security Policy + +## Reporting a Vulnerability + +**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.** + +Instead, report them privately via GitHub's [private vulnerability reporting](https://github.com/developmentseed/stac-auth-proxy/security/advisories/new) (the "Report a vulnerability" button on the repository's [Security tab](https://github.com/developmentseed/stac-auth-proxy/security)). + +Please include as much of the following as you can: + +- A description of the issue and its impact (e.g. authentication bypass, filter bypass, data exposure) +- Steps to reproduce, ideally with a minimal configuration and example requests +- Affected version(s) and relevant configuration (e.g. enabled filters, upstream STAC API) +- Any suggested fix or mitigation + +## What to Expect + +- We aim to acknowledge reports within **5 business days**. +- We will keep you informed as we investigate and work on a fix. +- Once a fix is released, we will publish a [GitHub Security Advisory](https://github.com/developmentseed/stac-auth-proxy/security/advisories) and, where appropriate, request a CVE. Reporters are credited unless they prefer to remain anonymous. + +Please give us a reasonable amount of time to address the issue before any public disclosure. + +## Supported Versions + +Security fixes are applied to the latest release only. Please upgrade to the most recent version before reporting.