markdowneditor

Security Policy

SECURITY.md – private reporting, scope, safe harbor

소프트웨어 및 엔지니어링표준securitypolicy

사용법: Any project with users. The "do not open a public issue" line is the whole point – private channel only.

미리보기

Security Policy

Supported versions

VersionSupported
1.x (latest)Yes
< 1.0No

Reporting a vulnerability

Please do not open a public issue for security reports.

Report vulnerabilities privately via:

  • Email: [[email protected]]
  • GitHub private vulnerability reporting: repository → Security → "Report a vulnerability"

What to include

  • Description of the issue and potential impact
  • Steps to reproduce or proof-of-concept
  • Affected versions
  • Suggested fix if you have one (optional)

What to expect

StageTimeline
AcknowledgmentWithin 72 hours
Initial assessmentWithin 7 days
Fix or mitigationSeverity-dependent; critical issues prioritized
DisclosureCoordinated with reporter after fix is released

Scope

In scope: the application and its official releases.

Out of scope: issues in third-party dependencies (report upstream), social engineering, physical attacks, DoS via resource exhaustion already tracked.

Safe harbor

We will not pursue legal action against researchers who report in good faith, respect user privacy, and do not access or modify data that is not theirs.

관련 템플릿