Skip to content

Commit 1eefd6d

Browse files
Add how users should report security vulnerabilities for this repository (#2562)
## Proposed Changes Suggestion to add a notice on how to report security vulnerabilities. This is visible at https://github.com/sigp/lighthouse/security
1 parent ddbd4e6 commit 1eefd6d

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

SECURITY.md

+13
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
Please see [Releases](https://github.com/sigp/lighthouse/releases/). We recommend using the [most recently released version](https://github.com/sigp/lighthouse/releases/latest).
6+
7+
## Reporting a Vulnerability
8+
9+
Please send vulnerability reports to [email protected] and encrypt sensitive messages using our [PGP
10+
key](https://keybase.io/sigp/pgp_keys.asc?fingerprint=15e66d941f697e28f49381f426416dc3f30674b0).
11+
12+
**Please do not file a public ticket** mentioning the vulnerability, as doing so could increase the likelihood of the vulnerability being used before a fix has been created, released and installed on the network.
13+

0 commit comments

Comments
 (0)