Skip to content

Commit 07a93b9

Browse files
committed
"add SECURITY"
1 parent 1e59715 commit 07a93b9

File tree

1 file changed

+42
-0
lines changed

1 file changed

+42
-0
lines changed

SECURITY.md

+42
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
# Security Policies and Procedures
2+
3+
This document outlines security procedures and general policies for the CyberArk Conjur
4+
suite of tools and products.
5+
6+
* [Reporting a Bug](#reporting-a-bug)
7+
* [Disclosure Policy](#disclosure-policy)
8+
* [Comments on this Policy](#comments-on-this-policy)
9+
10+
## Reporting a Bug
11+
12+
The CyberArk Conjur team and community take all security bugs in the Conjur suite seriously.
13+
Thank you for improving the security of the Conjur suite. We appreciate your efforts and
14+
responsible disclosure and will make every effort to acknowledge your
15+
contributions.
16+
17+
Report security bugs by emailing the lead maintainers at [email protected].
18+
19+
The maintainers will acknowledge your email within 2 business days. Subsequently, we will
20+
send a more detailed response within 2 business days of our acknowledgement indicating
21+
the next steps in handling your report. After the initial reply to your report, the security
22+
team will endeavor to keep you informed of the progress towards a fix and full
23+
announcement, and may ask for additional information or guidance.
24+
25+
Report security bugs in third-party modules to the person or team maintaining
26+
the module.
27+
28+
## Disclosure Policy
29+
30+
When the security team receives a security bug report, they will assign it to a
31+
primary handler. This person will coordinate the fix and release process,
32+
involving the following steps:
33+
34+
* Confirm the problem and determine the affected versions.
35+
* Audit code to find any potential similar problems.
36+
* Prepare fixes for all releases still under maintenance. These fixes will be
37+
released as fast as possible.
38+
39+
## Comments on this Policy
40+
41+
If you have suggestions on how this process could be improved please submit a
42+
pull request.

0 commit comments

Comments
 (0)