add a security policy (#3733)

* add a security policy

* use GitHub's private disclosure feature
This commit is contained in:
Marten Seemann 2023-03-28 09:24:28 +09:00 committed by GitHub
parent 91c747959a
commit f20b0d3d01
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

19
SECURITY.md Normal file
View file

@ -0,0 +1,19 @@
# Security Policy
quic-go still in development. This means that there may be problems in our protocols,
or there may be mistakes in our implementations.
We take security vulnerabilities very seriously. If you discover a security issue,
please bring it to our attention right away!
## Reporting a Vulnerability
If you find a vulnerability that may affect live deployments -- for example, by exposing
a remote execution exploit -- please [**report privately**](https://github.com/quic-go/quic-go/security/advisories/new).
Please **DO NOT file a public issue**.
If the issue is an implementation weakness that cannot be immediately exploited or
something not yet deployed, just discuss it openly.
## Reporting a non security bug
For non-security bugs, please simply file a GitHub [issue](https://github.com/quic-go/quic-go/issues/new).