Polymer / polymer

Our original Web Component library.
https://polymer-library.polymer-project.org/
BSD 3-Clause "New" or "Revised" License
22.05k stars 2.01k forks source link

Create SECURITY.md #5724

Open joycebrum opened 6 months ago

joycebrum commented 6 months ago

Reference Issue

Closes #5723

Description

I've created the SECURITY.md file considering the report vulnerability through security advisory, which is a new GitHub feature.

If you're interested in GitHub's feature, it must be activated for the repository:

  1. Open the repo's settings
  2. Click on Code security & analysis
  3. Click "Enable" for "Private vulnerability reporting (Beta)"

Let me know if you rather ask that vulnerabilities to be reported through an email instead.

Besides that, feel free to edit or suggest any changes to this document. It is supposed to reflect how the team want to receive and handle these reports.

Thanks!