From dc94b286d36e3537891d1d10e3e1e2e1307a34c8 Mon Sep 17 00:00:00 2001 From: Lawrence Lucas Large <162439255+LukeLarge@users.noreply.github.com> Date: Tue, 9 Dec 2025 21:00:30 -0600 Subject: [PATCH 1/3] Create SECURITY.md for security policy Add a security policy document outlining supported versions and vulnerability reporting. --- SECURITY.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..034e848 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ +# Security Policy + +## Supported Versions + +Use this section to tell people about which versions of your project are +currently being supported with security updates. + +| Version | Supported | +| ------- | ------------------ | +| 5.1.x | :white_check_mark: | +| 5.0.x | :x: | +| 4.0.x | :white_check_mark: | +| < 4.0 | :x: | + +## Reporting a Vulnerability + +Use this section to tell people how to report a vulnerability. + +Tell them where to go, how often they can expect to get an update on a +reported vulnerability, what to expect if the vulnerability is accepted or +declined, etc. From c1d11147a57edb40c346485ab8883eee6293e2ad Mon Sep 17 00:00:00 2001 From: Lawrence Lucas Large <162439255+LukeLarge@users.noreply.github.com> Date: Tue, 9 Dec 2025 21:06:47 -0600 Subject: [PATCH 2/3] Update SECURITY.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> --- SECURITY.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 034e848..ad15c30 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -14,8 +14,8 @@ currently being supported with security updates. ## Reporting a Vulnerability -Use this section to tell people how to report a vulnerability. +To report a security vulnerability, please email us at [security@example.com](mailto:security@example.com). -Tell them where to go, how often they can expect to get an update on a -reported vulnerability, what to expect if the vulnerability is accepted or -declined, etc. +Please include as much detail as possible about the vulnerability and steps to reproduce it. We request that you do not publicly disclose the issue until we have had a chance to investigate and address it. + +We will acknowledge receipt of your report within 2 business days. You can expect updates at least every 7 days until the issue is resolved. If the vulnerability is accepted, we will work with you to coordinate a fix and public disclosure. If the vulnerability is declined, we will provide a clear explanation of our reasoning. From b90a8787fe17894597d1876a1ffe778c8e3ad6ca Mon Sep 17 00:00:00 2001 From: Lawrence Lucas Large <162439255+LukeLarge@users.noreply.github.com> Date: Tue, 9 Dec 2025 21:07:30 -0600 Subject: [PATCH 3/3] Update SECURITY.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> --- SECURITY.md | 3 --- 1 file changed, 3 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index ad15c30..a9c16eb 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,9 +2,6 @@ ## Supported Versions -Use this section to tell people about which versions of your project are -currently being supported with security updates. - | Version | Supported | | ------- | ------------------ | | 5.1.x | :white_check_mark: |