public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
* [PATCH v2] Add security policy
@ 2025-11-19 17:09 Baurzhan Ismagulov
  2025-11-26  9:45 ` Zhihang Wei
  0 siblings, 1 reply; 2+ messages in thread
From: Baurzhan Ismagulov @ 2025-11-19 17:09 UTC (permalink / raw)
  To: isar-users

From: Zhihang Wei <wzh@ilbers.de>

Signed-off-by: Zhihang Wei <wzh@ilbers.de>
Signed-off-by: Baurzhan Ismagulov <ibr@ilbers.de>
---
 SECURITY.md | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)
 create mode 100644 SECURITY.md

diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 00000000..2ba12ff8
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,21 @@
+# Security Policy
+
+## Supported Versions
+
+Security updates will only be provided on top of the `master` branch.
+
+## Reporting a Vulnerability
+
+Please DO NOT report any potential security vulnerability via a public channel
+(mailing list, github issue, etc.). Instead, create a report via
+https://github.com/ilbers/isar/security/advisories/new or contact the
+maintainers by email at security@isar-build.org. Please provide a detailed
+description of the issue, the steps to reproduce it, the affected versions and,
+if already available, a proposal for a fix. You should receive a response
+within 15 business days. If for some reason you do not, please follow up by
+email to ensure we received your original message.
+
+If we confirm the issue as a vulnerability, we will open a Security Advisory on
+github and give credits for your report if desired. We follow the coordinated
+vulnerability disclosure model and will define an appropriate disclosure
+timeline together with you.
-- 
2.39.5

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20251119170906.1342632-1-ibr%40radix50.net.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2025-11-26  9:45 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-11-19 17:09 [PATCH v2] Add security policy Baurzhan Ismagulov
2025-11-26  9:45 ` Zhihang Wei

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox