From c9efbf9d97b65d67f6e87ee4b77bed0445bd7a9f Mon Sep 17 00:00:00 2001 From: Jelle Zijlstra Date: Sat, 18 Mar 2023 10:41:48 -0700 Subject: [PATCH] Add SECURITY.md (#3612) --- CHANGES.md | 3 +++ SECURITY.md | 11 +++++++++++ 2 files changed, 14 insertions(+) create mode 100644 SECURITY.md diff --git a/CHANGES.md b/CHANGES.md index 06a0ab7..e2f21cf 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -57,6 +57,9 @@ +- Document that only the most recent release is supported for security issues; + vulnerabilities should be reported through Tidelift (#3612) + ## 23.1.0 ### Highlights diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..4704950 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,11 @@ +# Security Policy + +## Supported Versions + +Only the latest non-prerelease version is supported. + +## Security contact information + +To report a security vulnerability, please use the +[Tidelift security contact](https://tidelift.com/security). Tidelift will coordinate the +fix and disclosure. -- 2.39.2