Skip to content

Commit 46ecb44

Browse files
author
Martin Gallo
committed
Clarified disclaimer and added security policy file.
1 parent f2d0696 commit 46ecb44

File tree

3 files changed

+34
-18
lines changed

3 files changed

+34
-18
lines changed

Diff for: MANIFEST.in

+2
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,8 @@
22
include ChangeLog.md
33
include COPYING
44
include README.md
5+
include SECURITY.md
6+
57
include requirements.txt
68
include requirements-docs.txt
79
include requirements-examples.txt

Diff for: README.md

+25-18
Original file line numberDiff line numberDiff line change
@@ -80,19 +80,8 @@ Documentation is available at [Read the Docs](https://pysap.readthedocs.io/en/la
8080
License
8181
-------
8282

83-
This library is distributed under the GPLv2 license. Check the `COPYING` file for
84-
more details.
85-
86-
87-
Disclaimer
88-
----------
89-
90-
The spirit of this open source initiative is hopefully to help the community to
91-
alleviate some of the hindrances associated with the implementation of
92-
networking protocols and stacks, aiming at speeding up research and educational
93-
activities. By no means this package is meant to be used in production
94-
environments / commercial products. If so, we would advise to include it into a
95-
proper SDLC process.
83+
This library is distributed under the GPLv2 license. Check the [COPYING](COPYING)
84+
file for more details.
9685

9786

9887
Authors
@@ -124,10 +113,28 @@ Contributions made by:
124113
* Andreas Hornig
125114
* Jennifer Hornig ([@gloomicious](https://github.com/gloomicious))
126115

116+
Disclaimer
117+
----------
127118

128-
Contact
129-
-------
119+
The spirit of this Open Source initiative is to help security researchers,
120+
and the community, speed up research and educational activities related to
121+
the implementation of networking protocols and stacks.
122+
123+
The information in this repository is for research and educational purposes
124+
only and is not intended to be used in production environments and/or as part
125+
of commercial products.
126+
127+
If you desire to use this tool or some part of it for your own uses, we
128+
recommend applying proper security development life cycle and secure coding
129+
practices, as well as generate and track the respective indicators of
130+
compromise according to your needs.
131+
132+
133+
Contact Us
134+
----------
135+
136+
Whether you want to report a bug, send a patch, or give some suggestions
137+
on this package, drop us a few lines at [email protected].
138+
139+
For security-related questions check our [security policy](SECURITY.md).
130140

131-
Whether you want to report a bug or give some suggestions on this package, drop
132-
us a few lines at `[email protected]` or contact the author email
133-

Diff for: SECURITY.md

+7
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
Security Policy
2+
===============
3+
4+
Although this initiative is not meant to be used in productive environments,
5+
if you consider that you have identified an issue that might affect the
6+
security of its users, or you understand that the tool is being abused,
7+
you can contact us at [email protected].

0 commit comments

Comments
 (0)