返回 CodeWhale
SECURITY.md
根目录 / SECURITY.md
1 # Security policy
2
3 ## Supported versions
4
5 Security fixes target the latest published stable Codewhale release. Please
6 upgrade before reproducing a report when possible.
7
8 | Version | Security fixes |
9 | --- | --- |
10 | Latest published stable release | Supported |
11 | Earlier releases | Upgrade to the latest stable release |
12 | Unreleased branches and development builds | Best effort; no release support commitment |
13
14 ## Report a vulnerability privately
15
16 Use [GitHub's private vulnerability report form](https://github.com/codewhale-hq/Codewhale/security/advisories/new).
17 Private vulnerability reporting is enabled for this repository. GitHub sends
18 the report to repository maintainers through a private security advisory.
19 Do not open a public issue or pull request containing an unpatched
20 vulnerability or exploit details.
21
22 Include the affected version or commit, operating system, a minimal
23 reproduction, expected and observed behavior, and the security impact.
24 Remove credentials, tokens, provider keys, personal data, and unrelated
25 repository contents. If a credential was exposed, rotate it through its
26 provider before sharing a redacted reproduction.
27
28 ## What to expect
29
30 Maintainers review reports and discuss reproduction, impact, and remediation
31 in the private advisory. Response and fix times depend on severity and
32 available capacity; there is no guaranteed response deadline. Please keep
33 exploit details private while a fix and disclosure timing are discussed.
34 When a fix is ready, maintainers use the advisory to coordinate publication
35 and affected versions. Reports that are ordinary bugs may be redirected to
36 the public issue tracker after sensitive details are removed.
37
37 lines MARKDOWN