From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Wed, 26 Nov 2025 10:45:55 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-ed1-f56.google.com (mail-ed1-f56.google.com [209.85.208.56]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 5AQ9jsud010460 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 26 Nov 2025 10:45:55 +0100 Received: by mail-ed1-f56.google.com with SMTP id 4fb4d7f45d1cf-640c4609713sf10293804a12.2 for ; Wed, 26 Nov 2025 01:45:55 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1764150349; cv=pass; d=google.com; s=arc-20240605; b=Yk2OIbr/EM0f+5aKuL69ljXXlHyaQ1C5IxTtKU86oqjmsV2GCxtrVnvFQks/GGrmWo crdX8gg4UKFLDiWkIcuVOowy70y8aUuR1ipJgENeOcIxqgmGuZ08tgvy1ejtzdgHs4/o p59XvEtlDKielqtJ7SXV6VLbsksd1tha9BeGLkTlyHk1laMUStPwJvEObi940Hs+3JBK Cg4wYb3olWEFz48Ey2/ARNugd2yo3FLDKYp3luJ3UlDD1NxHPIm025mUI1Z14D3RTfAZ nq2mf19It+ni88hF5wAZP8Y7nseX/s8WmJNXFbJnsitbyJcXXNmsE898xsmqnmYZHFtW /r7Q== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:in-reply-to:from:content-language :references:to:subject:user-agent:mime-version:date:message-id :sender:dkim-signature; bh=19534PzM4b7sEqp1Vz+QrmxhI3ySteM0QY9bVfii/YE=; fh=ETXeyMWc8x5CvV14mQw/V3coV/5plQCTNIltn/FWuWo=; b=bl+lDk7dOf2XT5irlGtFvGRvlhlSkhnupbpkayaXiUWsLpuyYut3Pvn7PNBtBA8aYc 3yL4olVNG0mzHyCVBHmNOC3I3pI+tJTDLjApHJ/l9/q4Tg8bevpOY5Kkhu+w9Ha/AndO yytVcBxZE0BnvDffnUTmM//GSeLH+3zltC9rwy1l0dvsStx7U5P4aRslyX2foD2I6FWO /devJho6lFJhlsnIimfK70cjSRKOtqMfpgOWTqE+txXgUivoo+3ud7ObVfQYchVh/SeI xSeFJcNDN/gMfPjQ/YVmHkevyUD7Xcts/RmBXqc5dbPEOYoP1z/0Mg3pYoIxJ3Ml4HrZ gl5A==; darn=ilbers.de ARC-Authentication-Results: i=2; gmr-mx.google.com; spf=pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=wzh@ilbers.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1764150349; x=1764755149; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:in-reply-to:from:content-language:references:to :subject:user-agent:mime-version:date:message-id:sender:from:to:cc :subject:date:message-id:reply-to; bh=19534PzM4b7sEqp1Vz+QrmxhI3ySteM0QY9bVfii/YE=; b=apI7ViT5VmJXttibGTe08LzD3aSVdhUWVj3cLtD/6Ldw+aNYylN2PnLOkcZUb637Ow 0Sxdo/TSDoxO7CFCXsKaeLgKXTtwtC93wh7lijOiKB4fJq7HGUmrCBGJ0ajq0Tn2LyTT Bzou6ccrcnnBUwHFNQcJ3ou8UQh3ER1HG09IxxUaHhpY1V3j+g4UznoeTgzibD7f/4G0 k0meyJP3SHUhMGME1esJITXr1USeHyLqUJyHQkk63T9Nf1rkkH0NnN/83d720i5xQ7RT tK0ryucIgUK5eUCInzVQwe+zwPNYLcBFAOtCbmlELR6oD7XjXbEs1FMH3tWjPo66mrXi vlNw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764150349; x=1764755149; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence :x-original-authentication-results:x-original-sender:in-reply-to :from:content-language:references:to:subject:user-agent:mime-version :date:message-id:x-beenthere:x-gm-message-state:sender:from:to:cc :subject:date:message-id:reply-to; bh=19534PzM4b7sEqp1Vz+QrmxhI3ySteM0QY9bVfii/YE=; b=JtKsqqmBLgHIh7DrcfxidHUp/w/V9e4jBicxBwMtLc5tHfEAbWDrnO3vv1UhwrmJ4q n9gsxKSb154fJIQ0Wr6oJSbVzrHSvACzGhwxq5+rSs8Uu5/WocIZN4fvBcFBrE098WSY 7UIEp83VY/Gi9Q3ml7bO5UDJtShC9xt1DZjYO0JwVp70gIL8D6SLyxFLrzFwYkkNFgmH bT0T4bLaK0EG/vBQnZYxpfVm+yyxu9KMswYtABMLQcAQbtt6o1VpWUZmqs3B07QUAHZn 5COEtYUCv0U/y8FpYI15PXB2C9VaauSpPFb4CGdA56HpmzfAbC4CZBExJFEUrRfliEmW t2nQ== Sender: isar-users@googlegroups.com X-Forwarded-Encrypted: i=2; AJvYcCV3djUYptX523j1oXt+9nXl3nM6DRfXaeLCVnO9PFjVbhy5AOOt72ygSO2jpUu5FkXrQ46s@ilbers.de X-Gm-Message-State: AOJu0Yxi/3EyHQRvkBjq3GzUYrB/bpl+LF42JZ7OOX0eBiwMgXWdLGRv Lqum99/Toexyk4Tm8l4Pki/qmXWIWo37Pbiu30CPa3n1d1TeAbxMyogs X-Google-Smtp-Source: AGHT+IEyWzBRRoL1L6sgO/NbrTgmzyauA6FVAPp1Hd4nZq2dQ7Ub2fqgfQ99MWw+SlviKUvHT5KzLw== X-Received: by 2002:a05:6402:34d0:b0:63b:ef0e:dfa7 with SMTP id 4fb4d7f45d1cf-645eb223e11mr5218594a12.6.1764150349373; Wed, 26 Nov 2025 01:45:49 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+Y+qRxLYktAV6pP2PMt3lsHOR8IKs3xn+4aJJpLkMWz4A==" Received: by 2002:a50:bac4:0:b0:644:f95b:b16f with SMTP id 4fb4d7f45d1cf-64536365cd3ls6303132a12.0.-pod-prod-08-eu; Wed, 26 Nov 2025 01:45:47 -0800 (PST) X-Forwarded-Encrypted: i=2; AJvYcCXntlVT9qSX5bXlWsUzf53Zgq6NDNMQoyEM2431vn3uhMPzdPHAA/C4qv5c8Re+1TO39AaXtrdqbt+4@googlegroups.com X-Received: by 2002:a17:907:9712:b0:b5f:c2f6:a172 with SMTP id a640c23a62f3a-b76c55f37damr571739266b.30.1764150346789; Wed, 26 Nov 2025 01:45:46 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1764150346; cv=none; d=google.com; s=arc-20240605; b=JGpQg5w1ipBSAJ6MTKJRx8pv6qT6Z9rL2MVUdMQDyQstkjNtZlNnPD/+rwKfGEIvJG /dSpv1G3dbXC9XwMi15nVkp77nJ9pHisCOqEBBy0P9KsAohBRCl0Yhn/vmzGChZkgf2o NGGFskI7mphmhHXJLCh6kv9Y3cw6MyYLH3dPZvJkt8Kuu+gk4l+gErF69zBChCGYbDrP ezmDZGcFwhGKXGUKjtt1w0dkGir+qxyzgPTItQAITvV6PCOLFvCRqBuOIDCPhibkX3ok 7+OgpL4wdbWBgTe7zkmDxpuVXsb7FZjRNZfplGHZKMQ+MmGqlthc8HK0U20XovcvM3v6 2jBQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=content-transfer-encoding:in-reply-to:from:content-language :references:to:subject:user-agent:mime-version:date:message-id; bh=jf0EdwmSrTKGceUXa0sKZuPuyf76ux+MY57Ns5T2U8w=; fh=u3Dlrqk027lVbD4k4tGIfW/ozRmuuGgmwf/O9dSOpqw=; b=C72j60JvwV6bMa5ZkePYjH3pkwIq7iPsPBkxVN3W1BmqZPS/3Bw41olEHNBERnez7r jpm0a43mXvlFrzcU9RzW+lX2Gl9wA+OFLX1pJgBSOiIZDiSQUT7bsFDK9fFAW8H0taMA xRPYy+Red1PeTp4poX4yulFms8t9HBW0Ap5RMMrzpiKgB8iKNmXNufYNuCjYdD/G1kMJ ThJiYc+jgAOUS1YrjMqG5XwWVMEPeYWVWobB4cBIhYKIt3k/qItr2ghMxEA9OguZefjO YynSJnkj/oWVXRl8QmUMSdYLNTc0+toQDdLNUluSnpPF5Nl+6ONFlo8oHnpfUJ7lQ9Ez Kcmw==; dara=google.com ARC-Authentication-Results: i=1; gmr-mx.google.com; spf=pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=wzh@ilbers.de Received: from shymkent.ilbers.de (shymkent.ilbers.de. [85.214.156.166]) by gmr-mx.google.com with ESMTPS id a640c23a62f3a-b76d6c6a4fdsi8426466b.3.2025.11.26.01.45.46 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 26 Nov 2025 01:45:46 -0800 (PST) Received-SPF: pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) client-ip=85.214.156.166; Received: from [192.168.178.117] ([88.130.203.42]) (authenticated bits=0) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPSA id 5AQ9jjS2010445 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 26 Nov 2025 10:45:46 +0100 Message-ID: <28931056-013c-401f-9f9d-22cfe730a0d9@ilbers.de> Date: Wed, 26 Nov 2025 10:45:45 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2] Add security policy To: Baurzhan Ismagulov , isar-users@googlegroups.com References: <20251119170906.1342632-1-ibr@radix50.net> Content-Language: en-US From: Zhihang Wei In-Reply-To: <20251119170906.1342632-1-ibr@radix50.net> Content-Type: text/plain; charset="UTF-8"; format=flowed X-Spam-Status: No, score=-4.6 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_EF,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-Original-Sender: wzh@ilbers.de X-Original-Authentication-Results: gmr-mx.google.com; spf=pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=wzh@ilbers.de Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-TUID: 5dfYjkvm9pPq Applied to next, thanks. On 11/19/25 18:09, Baurzhan Ismagulov wrote: > From: Zhihang Wei > > Signed-off-by: Zhihang Wei > Signed-off-by: Baurzhan Ismagulov > --- > SECURITY.md | 21 +++++++++++++++++++++ > 1 file changed, 21 insertions(+) > create mode 100644 SECURITY.md > > diff --git a/SECURITY.md b/SECURITY.md > new file mode 100644 > index 00000000..2ba12ff8 > --- /dev/null > +++ b/SECURITY.md > @@ -0,0 +1,21 @@ > +# Security Policy > + > +## Supported Versions > + > +Security updates will only be provided on top of the `master` branch. > + > +## Reporting a Vulnerability > + > +Please DO NOT report any potential security vulnerability via a public channel > +(mailing list, github issue, etc.). Instead, create a report via > +https://github.com/ilbers/isar/security/advisories/new or contact the > +maintainers by email at security@isar-build.org. Please provide a detailed > +description of the issue, the steps to reproduce it, the affected versions and, > +if already available, a proposal for a fix. You should receive a response > +within 15 business days. If for some reason you do not, please follow up by > +email to ensure we received your original message. > + > +If we confirm the issue as a vulnerability, we will open a Security Advisory on > +github and give credits for your report if desired. We follow the coordinated > +vulnerability disclosure model and will define an appropriate disclosure > +timeline together with you. -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/28931056-013c-401f-9f9d-22cfe730a0d9%40ilbers.de.