diff --git a/README.md b/README.md index 4f697b1ad..c2830250b 100644 --- a/README.md +++ b/README.md @@ -103,9 +103,7 @@ We ask that you not open a GitHub Issue for help, only for bug reports. **Reporting Security Issues** -In case you think to have found a security issue with libgit2, please do not -open a public issue. Instead, you can report the issue to the private mailing -list [security@libgit2.com](mailto:security@libgit2.com). +Please have a look at SECURITY.md. What It Can Do ============== diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..f98eebf50 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,14 @@ +# Security Policy + +## Supported Versions + +This project will always provide security fixes for the latest two released +versions. E.g. if the latest version is v0.28.x, then we will provide security +fixes for both v0.28.x and v0.27.y, but no later versions. + +## Reporting a Vulnerability + +In case you think to have found a security issue with libgit2, please do not +open a public issue. Instead, you can report the issue to the private mailing +list [security@libgit2.com](mailto:security@libgit2.com). We will acknowledge +receipt of your message in at most three days and try to clarify further steps.