Skip to content

Commit 9fc9b1f

Browse files
committed
Add SECURITY.md policy file
- Document supported versions (6.0.0+) - Add vulnerability reporting process - Specify security update policy for minor versions
1 parent d1624e5 commit 9fc9b1f

File tree

1 file changed

+35
-0
lines changed

1 file changed

+35
-0
lines changed

SECURITY.md

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
We officially support version **6.0.0 and above** of the YDB JavaScript SDK packages.
6+
7+
| Version | Supported |
8+
| ------- | ------------------ |
9+
| 6.x.x | :white_check_mark: |
10+
| < 6.0.0 | :x: |
11+
12+
## Reporting a Vulnerability
13+
14+
If you discover a security vulnerability, please do **NOT** open a public issue. Instead, please report it privately:
15+
16+
**Email:** security@ydb.tech
17+
18+
**Subject:** Security Vulnerability Report - YDB JS SDK
19+
20+
Please include:
21+
22+
- A description of the vulnerability
23+
- Steps to reproduce the issue
24+
- Potential impact
25+
- Suggested fix (if any)
26+
27+
## Security Updates
28+
29+
- Security patches are applied to the latest minor version of the current major version
30+
- Users are encouraged to upgrade to the latest version to receive security updates
31+
- Versions below 6.0.0 do not receive security updates
32+
33+
## Node.js Version Requirements
34+
35+
This SDK requires Node.js version **20.19.0 or higher**. Please ensure you're using a supported Node.js version to receive security updates from the Node.js project.

0 commit comments

Comments
 (0)