chore: add security policy

This commit is contained in:
Jan De Dobbeleer 2022-09-08 08:47:19 +02:00 committed by GitHub
parent 66a90f79df
commit 9e68535846
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

16
SECURITY.md Normal file
View file

@ -0,0 +1,16 @@
# Security Policy
## Supported Versions
Only the latest [release][releases] is supported.
## Reporting a Vulnerability
Vulnerabilities can be send in via [email][email] to avoid publishing in the open.
Oh My Posh does not have a bountry program, neither do we respond to beg bounties.
For valid security concerns, you can expect a response within 48 hours,
and credit is given once an acceptable fix is found and published.
[releases]: https://github.com/JanDeDobbeleer/oh-my-posh/releases
[email]: mailto:security@ohmyposh.dev