|
1 | 1 | # Security Policy |
2 | | - |
| 2 | + |
3 | 3 | ## Supported Versions |
4 | | - |
| 4 | + |
5 | 5 | | Version | Supported | |
6 | 6 | | ------- | ------------------ | |
7 | 7 | | latest | :white_check_mark: | |
8 | | - |
| 8 | + |
9 | 9 | ## Reporting a Vulnerability |
10 | | - |
11 | | -Even though this repository exists to prove that `1 == 1`, we take security |
12 | | -seriously. If you discover a vulnerability (or somehow find a way to make |
13 | | -`1 != 1`), please report it responsibly. |
14 | | - |
15 | | -**Do not open a public GitHub issue for security vulnerabilities.** |
16 | | - |
17 | | -### How to Report |
18 | | - |
19 | | -Please report security issues by emailing the maintainer directly: |
20 | | - |
21 | | -📧 **pycontributors@gmail.com** |
22 | | - |
23 | | -Include the following in your report: |
24 | | - |
25 | | -- A description of the vulnerability |
26 | | -- Steps to reproduce the issue |
27 | | -- The potential impact |
28 | | -- Any suggested fixes (optional, but appreciated) |
29 | | -### What to Expect |
30 | | - |
31 | | -- **Acknowledgement** within 48 hours of your report |
32 | | -- **Status update** within 7 days as we investigate |
33 | | -- **Credit** in the fix commit/release notes if you wish (just let us know) |
34 | | -We ask that you give us reasonable time to address the issue before any public |
35 | | -disclosure. We appreciate responsible disclosure and will do our best to resolve |
36 | | -confirmed vulnerabilities promptly. |
37 | | - |
| 10 | + |
| 11 | +If you discover a security vulnerability within is-one-one, please send an email to the maintainers. All security vulnerabilities will be promptly addressed. |
| 12 | +Report on dakshjain1265@gmail.com |
| 13 | +Please do not report security vulnerabilities through public GitHub issues. |
| 14 | + |
| 15 | +## Disclosure Policy |
| 16 | + |
| 17 | +When we receive a security bug report, we will: |
| 18 | + |
| 19 | +1. Confirm receipt of the vulnerability report |
| 20 | +2. Investigate and determine the impact |
| 21 | +3. Work on a fix |
| 22 | +4. Release the fix and publicly announce the vulnerability |
| 23 | + |
| 24 | +We appreciate your help in keeping the project secure. |
| 25 | + |
| 26 | + |
38 | 27 | ## Scope |
39 | 28 |
|
40 | 29 | This policy applies to the source code in this repository. Since this project |
41 | | -is a collection of Python functions that confirm `1 == 1`, the attack surface |
| 30 | +is a SANDBOX repository and collection of Python functions that confirm `1 == 1`, the attack surface |
42 | 31 | is blessedly small — but we still want to handle any concerns properly. |
43 | | - |
| 32 | + |
44 | 33 | ## Attribution |
45 | 34 |
|
46 | 35 | This security policy was created following the guidelines recommended by |
47 | 36 | [GitHub's security advisories documentation](https://docs.github.com/en/code-security/security-advisories). |
| 37 | + |
| 38 | + |
| 39 | + |
0 commit comments