summaryrefslogtreecommitdiff
path: root/.github
diff options
context:
space:
mode:
authorJulian Berman <Julian@GrayVines.com>2019-11-17 19:26:59 -0500
committerJulian Berman <Julian@GrayVines.com>2019-11-17 19:29:05 -0500
commit99868e2394fd3245b200763e9f28043b6d59f051 (patch)
tree85d0d2c055cdaaf7eca5eabdd643e466651ef1f7 /.github
parentaff9a3d4c00c03b9a43f8e2c3372311f6c6be1c5 (diff)
downloadjsonschema-99868e2394fd3245b200763e9f28043b6d59f051.tar.gz
Add a disclosure policy.
Diffstat (limited to '.github')
-rw-r--r--.github/SECURITY.md21
1 files changed, 21 insertions, 0 deletions
diff --git a/.github/SECURITY.md b/.github/SECURITY.md
new file mode 100644
index 0000000..fd524e9
--- /dev/null
+++ b/.github/SECURITY.md
@@ -0,0 +1,21 @@
+# Security Policy
+
+## Supported Versions
+
+In general, only the latest released ``jsonschema`` version is supported
+and will receive updates.
+
+## Reporting a Vulnerability
+
+To report a security vulnerability, please send an email to
+``Julian+Security@GrayVines.com`` with subject line ``SECURITY
+(jsonschema)``.
+
+I will do my best to respond within 48 hours to acknowledge the message
+and discuss further steps.
+
+If the vulnerability is accepted, an advisory will be sent out via
+GitHub's security advisory functionality.
+
+For non-sensitive discussion related to this policy itself, feel free to
+open an issue on the issue tracker.