Skip to content

Commit

Permalink
Add security policy document (GH-372)
Browse files Browse the repository at this point in the history
  • Loading branch information
pnacht committed Jun 16, 2023
1 parent 9468190 commit ea11793
Showing 1 changed file with 20 additions and 0 deletions.
20 changes: 20 additions & 0 deletions SECURITY.md
@@ -0,0 +1,20 @@
# Security Policy

If you have discovered a security vulnerability in this project, please report it
privately. **Do not disclose it as a public issue.** This gives us time to work with you
to fix the issue before public exposure, reducing the chance that the exploit will be
used before a patch is released.

Please submit the report through the
[Launchpad bug-tracker](https://bugs.launchpad.net/lxml/+filebug) (you may need to
create an account and log in). Make sure to mark the "🔒 This bug is a security
vulnerability" checkbox before submitting the report. This ensures the bug can only be
seen by the security group.

Please provide the following information in your report:

- A description of the vulnerability and its impact
- How to reproduce the issue

This project is maintained by a few maintainers on a reasonable-effort basis. As such,
we ask that you give us 90 days to work on a fix before public exposure.

0 comments on commit ea11793

Please sign in to comment.