Skip to content

Commit 9297cf3

Browse files
committed
Add new security policy
1 parent 1cb08e8 commit 9297cf3

File tree

1 file changed

+26
-0
lines changed

1 file changed

+26
-0
lines changed

SECURITY.md

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
# Security Policy
2+
3+
4+
## Supported Versions
5+
6+
Spyder-Kernels normally supports the version supporting the latest versions of Spyder with bug fixes, security updates and compatibility improvements.
7+
Additionally, the previous feature (major or minor) release will be supported for critical security and bug fixes only for two months following the release of a new Spyder feature version.
8+
9+
The following summarizes the support status of recent Spyder-Kernels versions.
10+
11+
| Version | Supported |
12+
| -------- | ------------------ |
13+
| 3.0.x | :heavy_check_mark: |
14+
| <3 | :x: |
15+
16+
17+
18+
## Reporting a Vulnerability
19+
20+
If you believe you've discovered a security vulnerability in Spyder-Kernels, please use open a new security advisory with [our GitHub repo's private vulnerability reporting](https://github.com/spyder-ide/spyder-kernels/security/advisories/new).
21+
Please be sure to carefully document the vulnerability, including a summary, describing the impacts, identifying the line(s) of code affected, stating the conditions under which it is exploitable and including a minimal reproducible test case.
22+
Further information and advice or patches on how to mitigate it is always welcome.
23+
You can usually expect to hear back within 1 week, at which point we'll inform you of our evaluation of the vulnerability and what steps we plan to take, and will reach out if we need further clarification from you.
24+
We'll discuss and update the advisory thread, and are happy to update you on its status should you further inquire.
25+
While this is a volunteer project and we don't have financial compensation to offer, we can certainly publicly thank and credit you for your help if you would like.
26+
Thanks!

0 commit comments

Comments
 (0)