Skip to content

Security: greggh/base-project-template

Security

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
1.0.x
0.9.x
0.8.x
< 0.8

Reporting a Vulnerability

We take the security of our project seriously. If you believe you've found a security vulnerability, please follow these steps:

  1. Do not disclose the vulnerability publicly
  2. Email [security@example.com] with details about the vulnerability
    • Include steps to reproduce
    • Include potential impact
    • If possible, include suggestions for remediation
  3. Allow time for response and remediation
    • We aim to respond to security reports within 48 hours
    • We'll keep you updated on our progress addressing the issue

Security Response Process

When a security vulnerability is reported:

  1. We will confirm receipt of the vulnerability report
  2. We will investigate and validate the reported issue
  3. We will develop and test a fix
  4. We will release a security update
  5. We will publicly disclose the issue after a fix is available

Security Best Practices for Users

  • Keep the project updated to the latest supported version
  • Apply security patches promptly
  • [Any other security recommendations specific to your project]

Security Updates

Security updates will be released as:

  • Patch versions for supported releases
  • Security advisories on GitHub
  • Announcements in our release notes

Past Security Advisories

[List of past security advisories or link to GitHub Security Advisories]

There aren’t any published security advisories