diff --git a/CHANGES.md b/CHANGES.md index 06a0ab7e9eb..e2f21cf8f8a 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -57,6 +57,9 @@ +- Document that only the most recent release is supported for security issues; + vulnerabilities should be reported through Tidelift (#3612) + ## 23.1.0 ### Highlights diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000000..47049501183 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,11 @@ +# Security Policy + +## Supported Versions + +Only the latest non-prerelease version is supported. + +## Security contact information + +To report a security vulnerability, please use the +[Tidelift security contact](https://tidelift.com/security). Tidelift will coordinate the +fix and disclosure.