From 5f52ff54a14e0c575b9bc5accabd6512725a0bea Mon Sep 17 00:00:00 2001 From: Jelle Zijlstra Date: Fri, 17 Mar 2023 21:35:09 -0700 Subject: [PATCH 1/3] Add SECURITY.md --- SECURITY.md | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000000..ac2022f2bce --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,11 @@ +# Security Policy + +## Supported Versions + +Only the latest non-prerelease version is supported. + +## Security contact information + +To report a security vulnerability, please use the +[Tidelift security contact](https://tidelift.com/security). +Tidelift will coordinate the fix and disclosure. From a7c6f27473d91200c342f71535b37d4e13b7f272 Mon Sep 17 00:00:00 2001 From: Jelle Zijlstra Date: Fri, 17 Mar 2023 21:37:08 -0700 Subject: [PATCH 2/3] changelog --- CHANGES.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/CHANGES.md b/CHANGES.md index eff2640a01e..41ac85d9b5e 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -54,6 +54,9 @@ +- Document that only the most recent release is supported for security issues; vulnerabilities + should be reported through Tidelift (#3612) + ## 23.1.0 ### Highlights From 0bc4193409066ae0950ccea228c8fd480e50dc8c Mon Sep 17 00:00:00 2001 From: Jelle Zijlstra Date: Fri, 17 Mar 2023 21:38:10 -0700 Subject: [PATCH 3/3] prettier --- CHANGES.md | 4 ++-- SECURITY.md | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/CHANGES.md b/CHANGES.md index 41ac85d9b5e..f4ad8cc24c3 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -54,8 +54,8 @@ -- Document that only the most recent release is supported for security issues; vulnerabilities - should be reported through Tidelift (#3612) +- Document that only the most recent release is supported for security issues; + vulnerabilities should be reported through Tidelift (#3612) ## 23.1.0 diff --git a/SECURITY.md b/SECURITY.md index ac2022f2bce..47049501183 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -7,5 +7,5 @@ Only the latest non-prerelease version is supported. ## Security contact information To report a security vulnerability, please use the -[Tidelift security contact](https://tidelift.com/security). -Tidelift will coordinate the fix and disclosure. +[Tidelift security contact](https://tidelift.com/security). Tidelift will coordinate the +fix and disclosure.