Skip to content

Commit ac4e9e4

Browse files
feat: Add SECURITY to show doc on reporting a security bug
Signed-off-by: Harika Nittala <lnittala@amd.com>
1 parent 9bbb7d6 commit ac4e9e4

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

SECURITY.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# Security and Disclosure Information Policy for the sev-certify project
2+
3+
* [Reporting a Security bug](#Reporting-a-Security-bug)
4+
* [Security bug Response](#Security-bug-Response)
5+
6+
## Reporting a Security bug
7+
8+
If you think you've identified a security issue in a sev-certify project,
9+
please DO NOT report the issue publicly via the Github issue tracker,
10+
mailing list, or IRC. Instead, send an email to our [project maintainers](CONTRIBUTING.md#project-maintainers).
11+
12+
Please do **not** create a public issue.
13+
14+
## Security bug Response
15+
16+
Each report is acknowledged and analyzed by the core maintainers within 5 working days.
17+
18+
Any vulnerability information shared with core maintainers stays within a sev-certify project
19+
and will not be disseminated to other projects unless it is necessary to get the issue fixed.
20+
21+
As the security issue moves from triage, to an identified fix, to release planning, the core
22+
maintainers will keep the reporter updated.

0 commit comments

Comments
 (0)