diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000000..f77b7bbee0 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,17 @@ +# Security Policy + +## Supported Versions + +Security updates are provided through new releases of the VS Code extensions and library in this repository. + +Supported versions: +- The latest published releases are supported. +- Older releases may not receive security fixes; please upgrade to the latest version. + +## Reporting a Vulnerability + +Please report security vulnerabilities **privately** via GitHub Security Advisories. + +Go to this repository’s **Security** tab and click **Report a vulnerability**. Do not open public issues for security reports. + +You can expect an initial response within 3 business days. If accepted, we will work with you on a fix and coordinate disclosure; if declined, we will provide a brief explanation.