summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSebastian Pipping <sebastian@pipping.org>2023-04-06 21:28:44 +0200
committerGitHub <noreply@github.com>2023-04-06 21:28:44 +0200
commitb4ddad5542eee987d0003297f9f4e2eed42707c0 (patch)
tree434bd86b4306de6d36696fa6a4eda1bf37e3f8a9
parentd8f43d6757af5ca5aae6cc185d6481f37f6c3be2 (diff)
parente055155fa0bfc9216c5a653cb2f8aeae84dc5dc2 (diff)
downloadlibexpat-git-b4ddad5542eee987d0003297f9f4e2eed42707c0.tar.gz
Merge pull request #701 from joycebrum/master
Create a Security Policy
-rw-r--r--SECURITY.md13
1 files changed, 13 insertions, 0 deletions
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 00000000..05937984
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,13 @@
+# Security Policy
+
+If you have discovered a security vulnerability in this project, please report it privately. **Do not disclose it as a public issue.** This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.
+
+To submit your report, please email [sebastian@pipping.org](mailto:sebastian@pipping.org) .
+
+Please provide at least the following information in your report:
+
+- A description of the vulnerability and its impact
+- How to reproduce the issue
+
+
+This project is maintained by a team of volunteers on a reasonable-effort basis. As such, please give us at least 90 days to work on a fix before public exposure.