summaryrefslogtreecommitdiff
path: root/SECURITY.md
diff options
context:
space:
mode:
authorChristian Cleberg <[email protected]>2026-03-24 21:48:23 -0500
committerChristian Cleberg <[email protected]>2026-03-24 21:48:23 -0500
commitcf587aa0573ac4f34e1effe70108a9eca82093ac (patch)
tree833e6f4961522e35b08af01b5f012983f8e34678 /SECURITY.md
downloadrune-1.0.0.tar.gz
rune-1.0.0.tar.bz2
rune-1.0.0.zip
v1.0v1.0.0
Diffstat (limited to 'SECURITY.md')
-rw-r--r--SECURITY.md33
1 files changed, 33 insertions, 0 deletions
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..1423145
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,33 @@
+# Security Policy
+
+## Supported Versions
+
+|Version|Supported|
+|-------|---------|
+| 1.x | ✅ Yes |
+| < 1.0 | ❌ No |
+
+---
+
+## Reporting a Vulnerability
+
+If you discover a security vulnerability, **do not open a public issue**.
+Instead:
+
+1. **Email** your report to [[email protected]](mailto:[email protected]).
+ Include:
+ - A detailed description of the vulnerability
+ - Steps to reproduce
+ - Any relevant context (e.g., affected versions, environment)
+2. **Response Time**: We will acknowledge your report within **3 business days**
+ and keep you updated on the progress.
+3. **Resolution**: If confirmed, we will:
+ - Provide an estimated timeline for a fix
+ - Work with you to verify the resolution
+ - Credit you for the discovery (if you wish)
+4. **Declined Reports**: If the report is invalid or out of scope, we will
+ explain why and close the issue.
+
+---
+
+**Thank you for helping improve the security of our project!**