Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Security Policy

## Supported Versions

Use this section to tell people about which versions of your project are
currently being supported with security updates.
Comment on lines +5 to +6
Copy link

Copilot AI Jan 3, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This placeholder text should be removed or replaced with actual project-specific guidance before merging. The current text is generic template content that doesn't provide value to users.

Copilot uses AI. Check for mistakes.

| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
| 5.0.x | :x: |
| 4.0.x | :white_check_mark: |
| < 4.0 | :x: |

## Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.
Comment on lines +17 to +21
Copy link

Copilot AI Jan 3, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This section contains only placeholder text without actual vulnerability reporting instructions. It should include specific information such as:

  • The email address or platform to use for reporting (e.g., security@project.org, GitHub Security Advisories)
  • Expected response time
  • The disclosure process and timeline
  • Any encryption keys or secure communication methods if applicable
Suggested change
Use this section to tell people how to report a vulnerability.
Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.
If you believe you have found a security vulnerability in this project, please report it to the maintainers rather than opening a public issue.
**Preferred method:** Use the private reporting channel provided by the hosting platform (for example, GitHub Security Advisories via the “Report a vulnerability” button on the repository’s Security tab).
**What to expect**
- We aim to acknowledge your report within **3 business days**.
- We aim to provide an initial assessment and, where possible, a remediation plan or next steps within **7–10 business days**.
- During investigation and remediation, we may request additional information or proof‑of‑concept details to reproduce the issue.
**Disclosure process and timeline**
- We ask that you **do not disclose** the vulnerability publicly until we have confirmed and fixed the issue or agreed on a coordinated disclosure date.
- For confirmed vulnerabilities affecting supported versions, we will work to develop and release a fix as soon as reasonably possible, prioritizing issues by severity and impact.
- After a fix or adequate mitigation is available, we may publish a security advisory describing the vulnerability, affected versions, and remediation steps.
- Our goal is to resolve and disclose most issues within **90 days** of initial report, but complex issues may require more time; in such cases, we will keep you informed of progress.
**Encryption**
At this time, we do not offer a dedicated encryption key for vulnerability reports. If you require an encrypted communication channel, please mention this in your initial report so we can arrange an appropriate method where possible.

Copilot uses AI. Check for mistakes.