Skip to content

Commit 54ee855

Browse files
committed
docs: add private security reporting policy
1 parent ee9b38a commit 54ee855

1 file changed

Lines changed: 17 additions & 0 deletions

File tree

‎SECURITY.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Security Policy
2+
3+
Please report suspected security vulnerabilities privately. Do not include
4+
exploit details in a public issue or pull request before coordinated disclosure.
5+
6+
Use **Report a vulnerability** on the
7+
[GitHub Security Advisories page](https://github.com/etr/libhttpserver/security/advisories)
8+
when it is available. Otherwise, email the maintainer at
9+
[electrictwister2000@gmail.com](mailto:electrictwister2000@gmail.com).
10+
11+
Include the affected version or commit, build configuration, dependency versions,
12+
impact, and reproduction steps or a minimal proof of concept. Reports affecting
13+
older releases are welcome; please identify the exact version tested.
14+
15+
The maintainer and reporter will coordinate a fix, disclosure timing, and credit.
16+
Please identify any existing CVE request so that duplicate identifiers can be
17+
avoided, and state how you would like to be credited.

0 commit comments

Comments
 (0)