Skip to content

Commit

Permalink
docs: added security.md file
Browse files Browse the repository at this point in the history
  • Loading branch information
lotyp committed Apr 19, 2024
1 parent ca925bd commit 17aefde
Showing 1 changed file with 49 additions and 0 deletions.
49 changes: 49 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
# Security Policy

Thank you for helping keep `cycle/database` and its users safe. We greatly appreciate your efforts to disclose security vulnerabilities responsibly.

<br>

## 🙋‍♂️ Supported Versions

Only certain versions of `cycle/database` are currently being maintained with security updates. Please use or upgrade to one of these supported versions:

| Version | Supported |
|---------|--------------------|
| 2.x | :white_check_mark: |

Please ensure that you are using one of these supported versions before reporting a security issue.

<br>

## 🗜️ Unsupported Versions

Versions listed below are no longer supported with security updates. We recommend upgrading to a supported version as soon as possible:

| Version | Supported |
|---------|-----------|
| 1.x | :x: |

<br>

## 🚨 Reporting a Vulnerability

We take all security bugs in `cycle/database` seriously. Please follow the instructions below to report security vulnerabilities.

### → How to Report

1. **GitHub Security Advisories**: Please report security issues directly through our GitHub Security Advisories page: https://github.com/cycle/database/security/advisories/new. This ensures that sensitive information is handled confidentially.

2. **Empty Security Issue**: After submitting through GitHub Security Advisories, please also create an empty security issue to alert us, as GitHub Advisories do not send automatic notifications. This can be done here: https://github.com/cycle/database/issues/new?assignees=&labels=type%3A+bug%2Cpriority%3A+high%2Ctype%3A+security&projects=&template=5-security-report.yml&title=%5BSecurity%5D%3A+

3. **Direct Contact**: For highly sensitive information, in addition to the GitHub Security Advisories, please email us directly at `[email protected]` with the subject line "SECURITY - Vulnerability Report". This will be treated with the highest priority.

Please do not discuss potential security issues in public forums or through our public GitHub issues tracker.

<br>

## ❌ Third-Party Bug Bounty Platforms

At this moment, we DO NOT accept reports from third-party bug bounty platforms to minimize risk. All vulnerability reports should come through the specified channels above.

<br>

0 comments on commit 17aefde

Please sign in to comment.