From: Jelle Zijlstra <jelle.zijlstra@gmail.com>
Date: Sat, 18 Mar 2023 17:41:48 +0000 (-0700)
Subject: Add SECURITY.md (#3612)
X-Git-Url: https://git.madduck.net/etc/vim.git/commitdiff_plain/c9efbf9d97b65d67f6e87ee4b77bed0445bd7a9f

Add SECURITY.md (#3612)
---

diff --git a/CHANGES.md b/CHANGES.md
index 06a0ab7..e2f21cf 100644
--- a/CHANGES.md
+++ b/CHANGES.md
@@ -57,6 +57,9 @@
 <!-- Major changes to documentation and policies. Small docs changes
      don't need a changelog entry. -->
 
+- Document that only the most recent release is supported for security issues;
+  vulnerabilities should be reported through Tidelift (#3612)
+
 ## 23.1.0
 
 ### Highlights
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..4704950
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,11 @@
+# Security Policy
+
+## Supported Versions
+
+Only the latest non-prerelease version is supported.
+
+## Security contact information
+
+To report a security vulnerability, please use the
+[Tidelift security contact](https://tidelift.com/security). Tidelift will coordinate the
+fix and disclosure.