From c969c302bc217135bcff9e44324c6bc342c3b865 Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Thu, 13 Mar 2025 19:44:48 +0100 Subject: [PATCH] =?UTF-8?q?=F0=9F=93=9D(docs)=20add=20SECURITY.md=20file?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Created SECURITY.md document outlining security policy, vulnerability reporting process, and responsible disclosure guidelines for the project. --- SECURITY.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..7493b05a --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Security Policy + +## Reporting a Vulnerability + +Security is very important to us. + +If you have any issue regarding security, please disclose the information responsibly submiting [this form](https://vdp.numerique.gouv.fr/p/Send-a-report?lang=en) and not by creating an issue on the repository. You can also email us at visio@numerique.gouv.fr + +We appreciate your effort to make Visio more secure. + +## Vulnerability disclosure policy + +Working with security issues in an open source project can be challenging, as we are required to disclose potential problems that could be exploited by attackers. With this in mind, our security fix policy is as follows: + +1. The Maintainers team will handle the fix as usual (Pull Request, + release). +2. In the release notes, we will include the identification numbers from the + GitHub Advisory Database (GHSA) and, if applicable, the Common Vulnerabilities + and Exposures (CVE) identifier for the vulnerability. +3. Once this grace period has passed, we will publish the vulnerability. + +By adhering to this security policy, we aim to address security concerns +effectively and responsibly in our open source software project.