Skip to content

Commit b4ea1c1

Browse files
committed
chore: add a security policy
1 parent 4a75ffd commit b4ea1c1

File tree

1 file changed

+30
-0
lines changed

1 file changed

+30
-0
lines changed

SECURITY.md

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
# Security Policy
2+
3+
This Eclipse Foundation Project adheres to the [Eclipse Foundation Vulnerability Reporting Policy](https://www.eclipse.org/security/policy/).
4+
5+
## How To Report a Vulnerability
6+
7+
If you think you have found a vulnerability in this repository, please report it to us through coordinated disclosure.
8+
9+
**Please do not report security vulnerabilities through public issues, discussions, or change requests.**
10+
11+
Instead, you can report it using one of the following ways:
12+
13+
* Contact the [Eclipse Foundation Security Team](mailto:security@eclipse-foundation.org) via email
14+
* Create a [confidential issue](https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/new?issuable_template=new_vulnerability) in the Eclipse Foundation Vulnerability Reporting Tracker
15+
16+
You can find more information about reporting and disclosure at the [Eclipse Foundation Security page](https://www.eclipse.org/security/).
17+
18+
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
19+
20+
* The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting)
21+
* Affected version(s)
22+
* Impact of the issue, including how an attacker might exploit the issue
23+
* Step-by-step instructions to reproduce the issue
24+
* The location of the affected source code (tag/branch/commit or direct URL)
25+
* Full paths of source file(s) related to the manifestation of the issue
26+
* Any special configuration required to reproduce the issue
27+
* Any log files that are related to this issue (if possible)
28+
* Proof-of-concept or exploit code (if possible)
29+
30+
This information will help us triage your report more quickly.

0 commit comments

Comments
 (0)