Skip to content

Commit 25235a5

Browse files
committed
add: security.md file
1 parent 84a8dce commit 25235a5

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed

SECURITY.md

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
# Security
2+
3+
Infraspec takes the security of our software products and services seriously, including all open-source code repositories managed through our organization, [Infraspec](https://github.com/infraspecdev/).
4+
5+
If you find any security vulnerabilities in our open source projects, please report them. We will ensure that your findings are passed along to the appropriate maintainers for remediation.
6+
7+
## Reporting Security Issues
8+
9+
If you believe you have found a security vulnerability in any Infraspec-owned repository, please report it to us through coordinated disclosure.
10+
11+
**Please do not report security vulnerabilities through public issues, discussions, or pull requests in Infraspec repositories.**
12+
13+
Instead, please send an email to <security@infrapsec.dev>.
14+
15+
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
16+
17+
* The type of issue (e.g., improper input handling, token exposure or API abuse in the spell and grammar checking process)
18+
* Full paths of source file(s) related to the manifestation of the issue
19+
* The location of the affected source code (tag/branch/commit or direct URL)
20+
* Any special configuration required to reproduce the issue
21+
* Step-by-step instructions to reproduce the issue
22+
* Proof-of-concept or exploit code (if possible)
23+
* Impact of the issue, including how an attacker might exploit the issue
24+
25+
This information will help us triage your report more quickly.

0 commit comments

Comments
 (0)