From 4f366901cd1a5f2c9c5eaf6441ede02e027e87a0 Mon Sep 17 00:00:00 2001 From: Alberto3903 Date: Tue, 13 Jan 2026 04:51:10 -0600 Subject: [PATCH] Create SECURITY.md for security policy Added a security policy document outlining supported versions and vulnerability reporting.https://github.com/Alberto3903/attest-build-provenance-CodeQL-https-github.com-github-markup-actions-workflows-githubcode-sc/actions/workflows/codeql-analysis.yml/badge.svg?branch=main&event=discussion --- SECURITY.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..034e848 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ +# Security Policy + +## Supported Versions + +Use this section to tell people about which versions of your project are +currently being supported with security updates. + +| Version | Supported | +| ------- | ------------------ | +| 5.1.x | :white_check_mark: | +| 5.0.x | :x: | +| 4.0.x | :white_check_mark: | +| < 4.0 | :x: | + +## Reporting a Vulnerability + +Use this section to tell people how to report a vulnerability. + +Tell them where to go, how often they can expect to get an update on a +reported vulnerability, what to expect if the vulnerability is accepted or +declined, etc.