docs: add SECURITY.md (AAA+ C-axis, ORDRE 36)
Vulnerability reporting policy scored to Scorecard Security-Policy 10/10: contact email, canonical repo URL with https://, response process, and a supported-versions table reflecting the actual v1.1.0 tag (only 1.x line exists). No docs/support-period.md or SBOM claims — neither exists in this repo.
This commit is contained in:
parent
ea8ec84a1e
commit
2427d36e7e
1 changed files with 31 additions and 0 deletions
31
SECURITY.md
Normal file
31
SECURITY.md
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
# Security policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
Report privately to <security@fromaitochitta.com> - do not open a
|
||||
public issue.
|
||||
Canonical repository: https://git.fromaitochitta.com/open/human-friendly-style
|
||||
|
||||
Please include the affected version or commit, a minimal reproduction,
|
||||
and the impact you see. We acknowledge every report within 5 working
|
||||
days, agree a fix and disclosure timeline with the reporter, and aim to
|
||||
disclose within 90 days of the initial report.
|
||||
|
||||
## Response process
|
||||
|
||||
1. Acknowledge within 5 working days.
|
||||
2. Triage and confirm severity within 10 working days.
|
||||
3. Develop and test a fix.
|
||||
4. Publish an advisory and credit the reporter unless they prefer
|
||||
to remain anonymous.
|
||||
|
||||
## Supported versions
|
||||
|
||||
| Version | Supported |
|
||||
|---------|-----------|
|
||||
| 1.x | Yes |
|
||||
| < 1.0 | No |
|
||||
|
||||
## Advisories
|
||||
|
||||
Security-relevant changes are noted in [CHANGELOG.md](CHANGELOG.md).
|
||||
Loading…
Add table
Add a link
Reference in a new issue