-
-
Notifications
You must be signed in to change notification settings - Fork 2
Add SECURITY.md with vulnerability reporting instructions #224
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -36,6 +36,7 @@ | |
| !GEMINI.md | ||
| !LICENSE | ||
| !README.md | ||
| !SECURITY.md | ||
| !vcpkg-configuration.json | ||
| !vcpkg.json | ||
|
|
||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,66 @@ | ||
| # Security Policy | ||
|
|
||
| ## Our Commitment | ||
|
|
||
| We always provide secure software to users via the latest release. The Live Background Removal Lite team takes the security of our software seriously, and we appreciate your efforts to responsibly disclose vulnerabilities. | ||
|
|
||
| ## Supported Versions | ||
|
|
||
| We provide security updates for the following versions: | ||
|
|
||
| | Version | Supported | | ||
| | ------- | ------------------ | | ||
| | Latest | :white_check_mark: | | ||
| | Others | :x: | | ||
|
|
||
| We recommend using the latest version available from our [releases page](https://kaito-tokyo.github.io/live-backgroundremoval-lite/) to ensure you have the most up-to-date security fixes. | ||
|
umireon marked this conversation as resolved.
|
||
|
|
||
| ## Reporting a Vulnerability | ||
|
|
||
| If you find a vulnerability, please report it to us immediately. We appreciate responsible disclosure and will work with you to resolve any security issues promptly. | ||
|
|
||
| ### How to Report | ||
|
|
||
| **Email:** [umireon+security@kaito.tokyo](mailto:umireon+security@kaito.tokyo) | ||
|
|
||
| When reporting a vulnerability, please include: | ||
|
|
||
| - A clear description of the vulnerability | ||
| - Steps to reproduce the issue | ||
| - Potential impact of the vulnerability | ||
| - Any suggested fixes or mitigation strategies | ||
| - Your contact information for follow-up | ||
|
|
||
| ### What to Expect | ||
|
|
||
| - **Acknowledgment:** We will acknowledge receipt of your vulnerability report within 48 hours. | ||
| - **Initial Assessment:** We will provide an initial assessment within 5 business days. | ||
| - **Regular Updates:** We will keep you informed of our progress throughout the investigation and resolution process. | ||
| - **Resolution:** We will work to resolve critical vulnerabilities as quickly as possible, typically within 30 days. | ||
|
|
||
| ### Responsible Disclosure | ||
|
|
||
| To protect our users, we ask that you: | ||
|
|
||
| - Do not publicly disclose the vulnerability until we have had a chance to address it | ||
| - Avoid accessing, modifying, or deleting other users' data | ||
| - Do not perform any attacks that could harm the availability or performance of our services | ||
| - Act in good faith and avoid violating any laws or regulations | ||
|
|
||
| ## Security Best Practices | ||
|
|
||
| When using Live Background Removal Lite: | ||
|
|
||
| - Always download from official sources ([releases page](https://kaito-tokyo.github.io/live-backgroundremoval-lite/)) | ||
|
umireon marked this conversation as resolved.
|
||
| - Keep your installation up to date with the latest version | ||
| - Report any suspicious behavior or unexpected functionality | ||
|
|
||
| ## Contact | ||
|
|
||
| For security-related questions or concerns, please contact us at [umireon+security@kaito.tokyo](mailto:umireon+security@kaito.tokyo). | ||
|
|
||
| For general questions, bug reports, or feature requests, please use our [GitHub Issues](https://github.com/kaito-tokyo/live-backgroundremoval-lite/issues) page. | ||
|
|
||
| --- | ||
|
|
||
| Thank you for helping us maintain the security and integrity of Live Background Removal Lite. | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.