mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-09-14 04:45:08 +00:00
add simple Security policy
This commit is contained in:
+26
@@ -0,0 +1,26 @@
|
||||
# Security policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
**Please do not report security vulnerabilities through public GitHub issues.**
|
||||
|
||||
Please report any vulnerability or any bug that could potentially affect the security of users' funds by mail to:
|
||||
|
||||
- [`kdmukai.vision749@passmail.net`](mailto:kdmukai.vision749@passmail.net)
|
||||
- [`nick@klockenga.net`](mailto:nick@klockenga.net)
|
||||
|
||||
In the subject type `[SeedSigner] Security Report: <short description>`
|
||||
and in the body a long description describing the issue. We aim to respond
|
||||
within one week and patch within 90 days.
|
||||
|
||||
### What to include
|
||||
|
||||
To help triage the report quickly, please include as much of the following as you can:
|
||||
|
||||
- The SeedSigner version
|
||||
- A description of the vulnerability and its impact
|
||||
- Steps to reproduce, ideally with a proof of concept
|
||||
|
||||
## Scope
|
||||
|
||||
This policy covers SeedSigner and related build repos (ie seedsigner-os).
|
||||
Reference in New Issue
Block a user