Skip to content

Commit

Permalink
chore: add scope to SECURITY
Browse files Browse the repository at this point in the history
  • Loading branch information
insertish committed Jun 12, 2023
1 parent 7f9f5cd commit 30eafac
Showing 1 changed file with 10 additions and 0 deletions.
10 changes: 10 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,16 @@

## Reporting a Vulnerability

Before reporting a vulnerability, please make sure it is in scope, for example you should report:

- Server vulnerabilities that may escalate user privileges or allow exfiltration of data.
- Client vulnerabilities that allow remote code execution or allow exfiltration of data.

You should not report anything that requires phyiscal access to a client machine to achieve, such as:

- Intercepting requests to visually affect client privilege (and not actual server privilege)
- Exfiltration of user credentials through third party sites

If you would like to report a security vulnerability,
please email **[[email protected]](mailto:[email protected])**,
this will open a new ticket in ticket system, you should receive a response
Expand Down

0 comments on commit 30eafac

Please sign in to comment.