docs(ms-ai-architect): legg til SECURITY.md (AAA+ runde 3, C-aksen)
Ny SECURITY.md i repo-roten etter felles mal for de 15 repoene i denne runden. Ingen versjon, tag eller katalog-ref endret. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BNpxhzuf5mydYeoQZ53wJw
This commit is contained in:
parent
440ff50df8
commit
740e461f4d
1 changed files with 32 additions and 0 deletions
32
SECURITY.md
Normal file
32
SECURITY.md
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
# Security policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
Report privately to <security@fromaitochitta.com> - do not open a
|
||||
public issue.
|
||||
Canonical repository: https://git.fromaitochitta.com/open/ms-ai-architect
|
||||
|
||||
Please include the affected version or commit, a minimal reproduction,
|
||||
and the impact you see. We acknowledge every report within 5 working
|
||||
days, agree a fix and disclosure timeline with the reporter, and aim to
|
||||
disclose within 90 days of the initial report.
|
||||
|
||||
## Response process
|
||||
|
||||
1. Acknowledge within 5 working days.
|
||||
2. Triage and confirm severity within 10 working days.
|
||||
3. Develop and test a fix.
|
||||
4. Publish an advisory and credit the reporter unless they prefer
|
||||
to remain anonymous.
|
||||
|
||||
## Supported versions
|
||||
|
||||
The latest tagged release (currently 1.17.0) is the only supported
|
||||
version. Security fixes land on `main` and are released as a new tag;
|
||||
we do not backport fixes to older releases. See `CHANGELOG.md` for the
|
||||
release history.
|
||||
|
||||
## Advisories
|
||||
|
||||
We publish advisories for confirmed vulnerabilities once a fix is
|
||||
available, crediting the reporter unless they request anonymity.
|
||||
Loading…
Add table
Add a link
Reference in a new issue