Skip to content

Commit b906cae

Browse files
authored
Create SECURITY.md
Signed-off-by: Marek Kaput <[email protected]>
1 parent 1046044 commit b906cae

File tree

1 file changed

+28
-0
lines changed

1 file changed

+28
-0
lines changed

SECURITY.md

+28
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
<!-- Use this section to tell people about which versions of your project are
6+
currently being supported with security updates.
7+
8+
| Version | Supported |
9+
| ------- | ------------------ |
10+
| 5.1.x | :white_check_mark: |
11+
| 5.0.x | :x: |
12+
| 4.0.x | :white_check_mark: |
13+
| < 4.0 | :x: |
14+
-->
15+
16+
Only the latest release is supported with security updates.
17+
18+
## Reporting a Vulnerability
19+
20+
If there are any vulnerabilities in **Scarb**, don't hesitate to _report them_.
21+
22+
1. If you found a vulnerability in **Cairo** language/compiler,
23+
please consult its own [security policy](https://github.com/starkware-libs/cairo/security/policy).
24+
2. Use GitHub Security site for reporting vulnerabilities.
25+
You can report one [here](https://github.com/software-mansion/scarb/security/advisories/new).
26+
3. Please **do not disclose the vulnerability publicly** until a fix is released!
27+
4. Once we have either a) published a fix, or b) declined to address the vulnerability for whatever reason,
28+
you are free to publicly disclose it.

0 commit comments

Comments
 (0)