Skip to content

Commit bd3ebff

Browse files
Create SECURITY.md
1 parent 8259ea6 commit bd3ebff

1 file changed

Lines changed: 29 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# Security Policy
2+
3+
As a U.S. Government agency, the General Services Administration (GSA) takes seriously our responsibility to protect the public's information, including financial and personal information, from unwarranted disclosure.
4+
5+
## Reporting a Vulnerability
6+
7+
Services operated by the U.S. General Services Administration (GSA)
8+
are covered by the **GSA Vulnerability Disclosure Program (VDP)**.
9+
10+
See the [GSA Vulnerability Disclosure Policy](https://gsa.gov/vulnerability-disclosure-policy)
11+
at <https://www.gsa.gov/vulnerability-disclosure-policy> for details including:
12+
13+
Please consult our policy for:
14+
* How to submit a report if you believe you have discovered a vulnerability.
15+
* GSA's coordinated disclosure policy.
16+
* Information on how you may conduct security research on GSA developed software and systems.
17+
* Important legal and policy guidelines.
18+
19+
## Supported Versions
20+
21+
Please note that only certain branches are supported with security updates.
22+
23+
| Version (Branch) | Supported |
24+
| ---------------- | ------------------ |
25+
| main | :white_check_mark: |
26+
| stage | :white_check_mark: |
27+
| develop | :white_check_mark: |
28+
29+
When using this code or reporting vulnerabilities please only use supported versions.

0 commit comments

Comments
 (0)