Skip to content

Commit e4f1c94

Browse files
authored
Add a SECURITY.md file (#1184)
2 parents 4103cad + 8b02eb2 commit e4f1c94

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

SECURITY.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
The latest minor release of Spegel receives patch updates for critical security vulnerabilities on a best-effort basis.
6+
7+
For guaranteed SLAs on security fixes and patches across multiple releases, enterprise support is available through [Kvick](https://kvick.dev).
8+
9+
## Reporting a Vulnerability
10+
11+
Please report security vulnerabilities through [GitHub Security Advisories](https://github.com/spegel-org/spegel/security/advisories/new). All reports are handled with priority.
12+
13+
We aim to acknowledge reports within 7 days and release patches for critical vulnerabilities within 30 days.
14+
15+
We request that security researchers follow responsible disclosure practices and allow us a reasonable time of 90 days to address the vulnerability before public disclosure.
16+
17+
With your permission, we will acknowledge your contribution in the release notes of the patch version.

0 commit comments

Comments
 (0)