Skip to content

Commit b4c3f9d

Browse files
authored
docs: add security policy (#4347)
This PR adds a SECURITY.md document describing how to report a vulnerability.
1 parent ffc8c2f commit b4c3f9d

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

SECURITY.md

+10
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
If you find a vulnerability, or evidence of one, please report it privately.
6+
7+
Vulnerabilities should be reported using [GitHub's mechanism for privately reporting a vulnerability](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability). Under the
8+
[main repository's security tab](https://github.com/github-aws-runners/terraform-aws-github-runner/security), click "Report a vulnerability" to open the advisory form.
9+
10+
A member of the terraform-aws-github-runner team will triage the reported vulnerability and if the vulnerability is accepted a security advisory will be published and all further communication will be done via that security advisory.

0 commit comments

Comments
 (0)