Skip to content

Commit f1275f9

Browse files
trasherstonebuzzcedric-anne
authored
Add security policy (#57)
* Add security policy * Update SECURITY.md Co-authored-by: Cédric Anne <canne@teclib.com> --------- Co-authored-by: Stanislas <skita@teclib.com> Co-authored-by: Cédric Anne <canne@teclib.com>
1 parent 3773abe commit f1275f9

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
Security Policy
2+
3+
**⚠️ Please never use standard issues to report security problems; vulnerabilities are published once a fix release is available. ⚠️**
4+
5+
## Reporting a Vulnerability
6+
7+
If you found a security issue, please contact us by mail at \[glpi-security AT ow2.org\].
8+
9+
You should provide us all details about the issue and the way to reproduce it.
10+
You may also provide a script that can be used to check the issue exists.
11+
12+
Once the report will be handled, and if the issue is not yet fixed (or in progress)
13+
we'll add it to the GitHub security tab, and add you as observer. Meanwhile,
14+
you will reserve a CVE for the issue.
15+
16+
Thank you for improving the security of GLPI and its plugins.
17+
18+
## Supported Versions
19+
20+
We follow the same version support policy as GLPI.
21+
This means that we provide security patches to versions of the plugin that target a version of GLPI itself maintained from a security point of view.

0 commit comments

Comments
 (0)