]> git.madduck.net Git - etc/vim.git/commitdiff

madduck's git repository

Every one of the projects in this repository is available at the canonical URL git://git.madduck.net/madduck/pub/<projectpath> — see each project's metadata for the exact URL.

All patches and comments are welcome. Please squash your changes to logical commits before using git-format-patch and git-send-email to patches@git.madduck.net. If you'd read over the Git project's submission guidelines and adhered to them, I'd be especially grateful.

SSH access, as well as push access can be individually arranged.

If you use my repositories frequently, consider adding the following snippet to ~/.gitconfig and using the third clone URL listed for each project:

[url "git://git.madduck.net/madduck/"]
  insteadOf = madduck:

Add SECURITY.md (#3612)
authorJelle Zijlstra <jelle.zijlstra@gmail.com>
Sat, 18 Mar 2023 17:41:48 +0000 (10:41 -0700)
committerGitHub <noreply@github.com>
Sat, 18 Mar 2023 17:41:48 +0000 (10:41 -0700)
CHANGES.md
SECURITY.md [new file with mode: 0644]

index 06a0ab7e9eb5df143f2d24d350c66d64d0780697..e2f21cf8f8a41905bcd7e40eb4cf4c23dbf07612 100644 (file)
@@ -57,6 +57,9 @@
 <!-- Major changes to documentation and policies. Small docs changes
      don't need a changelog entry. -->
 
+- Document that only the most recent release is supported for security issues;
+  vulnerabilities should be reported through Tidelift (#3612)
+
 ## 23.1.0
 
 ### Highlights
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644 (file)
index 0000000..4704950
--- /dev/null
@@ -0,0 +1,11 @@
+# Security Policy
+
+## Supported Versions
+
+Only the latest non-prerelease version is supported.
+
+## Security contact information
+
+To report a security vulnerability, please use the
+[Tidelift security contact](https://tidelift.com/security). Tidelift will coordinate the
+fix and disclosure.