Skip to content

Commit 9a55544

Browse files
committed
security: Add security policy
1 parent 2044858 commit 9a55544

1 file changed

Lines changed: 44 additions & 0 deletions

File tree

‎SECURITY.md‎

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
# Security Policy
2+
3+
## Reporting Security Issues
4+
5+
Please do not open public GitHub issues for security vulnerabilities.
6+
7+
Email security concerns to: mullassery@gmail.com
8+
9+
Include:
10+
- Description of the vulnerability
11+
- Steps to reproduce
12+
- Potential impact
13+
- Suggested fix (if any)
14+
15+
We will acknowledge receipt within 24 hours and provide updates on remediation progress.
16+
17+
## Supported Versions
18+
19+
| Version | Supported |
20+
|---------|-----------|
21+
| Latest | Yes |
22+
| Previous | Limited |
23+
| Older | No |
24+
25+
## Security Best Practices
26+
27+
- Always use the latest version
28+
- Report vulnerabilities privately
29+
- Never share vulnerability details publicly before patch
30+
- Use environment variables for secrets (not hardcoded)
31+
- Keep dependencies updated
32+
- Enable GitHub security features
33+
34+
## Vulnerability Disclosure
35+
36+
When a security issue is confirmed:
37+
1. We develop and test a fix
38+
2. We release a new version with security patch
39+
3. We notify users of the vulnerability and fix
40+
4. We credit the reporter (if desired)
41+
42+
## Contact
43+
44+
Security Team: mullassery@gmail.com

0 commit comments

Comments
 (0)