From: Zhihang Wei <wzh@ilbers.de>
To: Baurzhan Ismagulov <ibr@radix50.net>, isar-users@googlegroups.com
Subject: Re: [PATCH v2] Add security policy
Date: Wed, 26 Nov 2025 10:45:45 +0100 [thread overview]
Message-ID: <28931056-013c-401f-9f9d-22cfe730a0d9@ilbers.de> (raw)
In-Reply-To: <20251119170906.1342632-1-ibr@radix50.net>
Applied to next, thanks.
On 11/19/25 18:09, Baurzhan Ismagulov wrote:
> From: Zhihang Wei <wzh@ilbers.de>
>
> Signed-off-by: Zhihang Wei <wzh@ilbers.de>
> Signed-off-by: Baurzhan Ismagulov <ibr@ilbers.de>
> ---
> SECURITY.md | 21 +++++++++++++++++++++
> 1 file changed, 21 insertions(+)
> create mode 100644 SECURITY.md
>
> diff --git a/SECURITY.md b/SECURITY.md
> new file mode 100644
> index 00000000..2ba12ff8
> --- /dev/null
> +++ b/SECURITY.md
> @@ -0,0 +1,21 @@
> +# Security Policy
> +
> +## Supported Versions
> +
> +Security updates will only be provided on top of the `master` branch.
> +
> +## Reporting a Vulnerability
> +
> +Please DO NOT report any potential security vulnerability via a public channel
> +(mailing list, github issue, etc.). Instead, create a report via
> +https://github.com/ilbers/isar/security/advisories/new or contact the
> +maintainers by email at security@isar-build.org. Please provide a detailed
> +description of the issue, the steps to reproduce it, the affected versions and,
> +if already available, a proposal for a fix. You should receive a response
> +within 15 business days. If for some reason you do not, please follow up by
> +email to ensure we received your original message.
> +
> +If we confirm the issue as a vulnerability, we will open a Security Advisory on
> +github and give credits for your report if desired. We follow the coordinated
> +vulnerability disclosure model and will define an appropriate disclosure
> +timeline together with you.
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/28931056-013c-401f-9f9d-22cfe730a0d9%40ilbers.de.
prev parent reply other threads:[~2025-11-26 9:45 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-19 17:09 Baurzhan Ismagulov
2025-11-26 9:45 ` Zhihang Wei [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=28931056-013c-401f-9f9d-22cfe730a0d9@ilbers.de \
--to=wzh@ilbers.de \
--cc=ibr@radix50.net \
--cc=isar-users@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox