Skip to content

Commit c09945b

Browse files
Update SECURITY.md
1 parent 23fe0da commit c09945b

1 file changed

Lines changed: 6 additions & 26 deletions

File tree

SECURITY.md

Lines changed: 6 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,8 @@
1-
# Security Policy
1+
## Security-Focused Roles
22

3-
## Reporting a Vulnerability
3+
- **Security Maintainer:** Reviews security-related pull requests and coordinates vulnerability disclosures.
4+
- **Pentester:** Conducts regular penetration testing and reports findings.
5+
- **Incident Responder:** Handles security incidents and coordinates with affected users.
6+
- **DevSecOps Engineer:** Integrates security tools and monitors automated checks in CI/CD.
47

5-
If you discover a vulnerability in any of our projects, please follow these steps:
6-
7-
1. **Do not disclose the vulnerability publicly** until it has been resolved.
8-
2. **Contact us directly** at [security@khulnasoft.com](mailto:security@khulnasoft.com). Please include the following information in your report:
9-
- A description of the vulnerability
10-
- Steps to reproduce or a proof of concept (PoC)
11-
- Any relevant system/environment details (e.g., OS version, software version)
12-
3. **We will acknowledge receipt** of your report and work with you to resolve the issue.
13-
4. Once resolved, the vulnerability will be disclosed publicly, with appropriate credit given.
14-
15-
## Responsible Disclosure
16-
17-
We take security very seriously. Any security issue discovered should be reported directly to us, and we will ensure that the issue is patched and disclosed responsibly. By following this process, you help protect the integrity of this project and its users.
18-
19-
## Vulnerability Disclosure Timeline
20-
21-
- **Day 0**: Vulnerability report received.
22-
- **Day 1–3**: Acknowledgment and preliminary assessment.
23-
- **Day 4–14**: Fix development and testing.
24-
- **Day 15**: Public disclosure (with fixes) and credit given.
25-
26-
Please **do not** use the tools or exploits provided here to attack unauthorized systems. Follow legal guidelines in your local jurisdiction when testing systems.
27-
28-
Thank you for helping us keep our projects secure!
8+
Contact: [security@yourdomain.com](mailto:security@yourdomain.com)

0 commit comments

Comments
 (0)