Skip to content

Commit f7ad38f

Browse files
doc(security): amend outdated security policy info
1 parent ed8af76 commit f7ad38f

1 file changed

Lines changed: 14 additions & 4 deletions

File tree

SECURITY.md

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,11 +2,21 @@
22

33
## Supported Versions
44

5-
Only the latest version.
5+
Only the latest released version.
6+
7+
If you found a vulnerability that only applies to older versions but has been accidentally fixed recently, please also open a private advisory to let us evaluate if a backdated advisory should be necessary.
8+
9+
If you found a vulnerability in unreleased code (Git trunk), please verify that the latest release is not affected and then use the public issue and pull request workflow to submit your research.
610

711
## Reporting a Vulnerability
812

9-
Please report (suspected) security vulnerabilities to
10-
**[gotify@protonmail.com](mailto:gotify@protonmail.com)**. You will receive a
11-
response from us within a few days. If the issue is confirmed, we will release a
13+
Please report security vulnerabilities to
14+
[GitHub Private Advisory](https://github.com/gotify/server/security)
15+
or **[gotify@protonmail.com](mailto:gotify@protonmail.com)**. You will receive a
16+
response from us within a few days.
17+
18+
If the issue is confirmed, we will release a
1219
patch as soon as possible.
20+
Additionally, we will submit findings that demonstrate the necessity for
21+
user triage and align to CNA vulnerability determination standards
22+
to the GitHub CNA Program.

0 commit comments

Comments
 (0)