From e7d1ccf1e05da6f165b9df9d3dca731bd16b7a68 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?IsabelSch=C3=B6ps=28Vitalik=20Buterin=29?= <127110010+IsabelSchoepd@users.noreply.github.com> Date: Mon, 25 Sep 2023 16:15:53 +0200 Subject: [PATCH] SECURITY.md --- SECURITY.md | 32 +++++--------------------------- 1 file changed, 5 insertions(+), 27 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index d9a8762..337b1dc 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,31 +1,9 @@ -Thanks for helping make GitHub safe for everyone. - -## Security - -GitHub takes the security of our software products and services seriously, including all of the open source code repositories managed through our GitHub organizations, such as [GitHub](https://github.com/GitHub). - -Even though [open source repositories are outside of the scope of our bug bounty program](https://bounty.github.com/index.html#scope) and therefore not eligible for bounty rewards, we will ensure that your finding gets passed along to the appropriate maintainers for remediation. - -## Reporting Security Issues +IsabelSchöps +![IMG_3930](https://github.com/github/.github/assets/127110010/50f30724-c11f-4b3a-9be8-ae6fc4815feb) -If you believe you have found a security vulnerability in any GitHub-owned repository, please report it to us through coordinated disclosure. -**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.** - -Instead, please send an email to opensource-security[@]github.com. - -Please include as much of the information listed below as you can to help us better understand and resolve the issue: - - * The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting) - * Full paths of source file(s) related to the manifestation of the issue - * The location of the affected source code (tag/branch/commit or direct URL) - * Any special configuration required to reproduce the issue - * Step-by-step instructions to reproduce the issue - * Proof-of-concept or exploit code (if possible) - * Impact of the issue, including how an attacker might exploit the issue - -This information will help us triage your report more quickly. +Thanks for helping make GitHub safe for everyone. -## Policy +## Security -See [GitHub's Safe Harbor Policy](https://docs.github.com/en/site-policy/security-policies/github-bug-bounty-program-legal-safe-harbor) +GitHub takes the security of our software products and services seriously, including all of the open source code repositories managed through our GitHub organizations, such as