mirror of
https://github.com/radzenhq/radzen-blazor.git
synced 2026-02-04 05:35:44 +00:00
Create SECURITY.md
This commit is contained in:
37
SECURITY.md
Normal file
37
SECURITY.md
Normal file
@@ -0,0 +1,37 @@
|
||||
## Security
|
||||
|
||||
Radzen Ltd. takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organization.
|
||||
|
||||
## Reporting Security Issues
|
||||
|
||||
**Please do not report security vulnerabilities through public GitHub issues.**
|
||||
|
||||
Instead, send an email to [security@radzen.com](mailto:security@radzen.com).
|
||||
|
||||
Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:
|
||||
|
||||
- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
|
||||
- Full paths of source file(s) related to the manifestation of the issue
|
||||
- The location of the affected source code (tag/branch/commit or direct URL)
|
||||
- Any special configuration required to reproduce the issue
|
||||
- Step-by-step instructions to reproduce the issue
|
||||
- Proof-of-concept or exploit code (if possible)
|
||||
- Impact of the issue, including how an attacker might exploit the issue
|
||||
|
||||
This information will help us triage your report more quickly.
|
||||
|
||||
## Preferred Languages
|
||||
|
||||
We prefer all communications to be in English.
|
||||
|
||||
## Policy
|
||||
|
||||
Radzen Ltd. follows the principle of [Coordinated Vulnerability Disclosure](https://insights.sei.cmu.edu/documents/1945/2017_003_001_503340.pdf).
|
||||
|
||||
## Supported versions
|
||||
The versions of the project that are currently supported with security updates.
|
||||
|
||||
| Version | Supported |
|
||||
| ------: | :----------------- |
|
||||
| 4.x | :white_check_mark: |
|
||||
| < 4.0 | :x: |
|
||||
Reference in New Issue
Block a user