diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..33ebccb --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,37 @@ +# Security Policy + +## Reporting a Vulnerability + +Please report security vulnerabilities to +[**security@pgedge.com**](mailto:security@pgedge.com), which reaches the +pgEdge security team. + +Please do not open a public issue for a suspected vulnerability. + +Tell us the product and version, what the impact is, and how to reproduce +it. You do not need to sign anything or hold a pgEdge contract to report to +us. + +We acknowledge reports within five business days, tell you the outcome of +our assessment, and tell you before we publish anything. + +## Supported Versions + +Security fixes are provided for the latest release of each product. Where a +product has its own published support lifecycle, that lifecycle governs. + +## Scope and Safe Harbour + +What is in scope, our safe harbour terms, and how we handle coordinated +disclosure and CVE identifiers are all set out in the pgEdge Vulnerability +Disclosure Statement: + +[**https://docs.pgedge.com/security**](https://docs.pgedge.com/security) + +You may test this software freely in an environment you control. Testing +pgEdge Cloud requires prior written authorisation — see the statement. + +## Published Advisories + +Advisories are published under the Security tab of the repository for the +affected product.