-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* chore: initial commit * docs: add initial file Signed-off-by: Jorge García Rey <[email protected]> * docs: add initial file Signed-off-by: Jorge García Rey <[email protected]> * docs: add security section in README Signed-off-by: Jorge García Rey <[email protected]> --------- Signed-off-by: Jorge García Rey <[email protected]>
- Loading branch information
1 parent
6e5c216
commit ad6753c
Showing
3 changed files
with
51 additions
and
11 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
# Security | ||
|
||
We at Inditex believe that responsible disclosure of security vulnerabilities helps us ensure the security and privacy | ||
of all opensource community. | ||
|
||
If you believe you have found a security vulnerability in any Inditex repository that meets Inditex definition of a | ||
security vulnerability, please report it to us as described below. We appreciate the hard work maintainers put into | ||
fixing vulnerabilities and understand that sometimes more time is required to properly address an issue. | ||
|
||
## Reporting security issues | ||
|
||
> [!CAUTION] | ||
> Do not file public issues on GitHub for security vulnerabilities | ||
* Let us know by submitting the finding through our [disclosure submission program](https://inditex.responsibledisclosure.com/) | ||
as soon as possible, upon discovery of a potential security issue. | ||
* Once we've assessed your report, we will create a GitHub "security advisory", which will allow the reporter and | ||
Inditex team to work on the issue in a confidential manner. We will invite you as a collaborator to the advisory and any | ||
needed trusted persons. | ||
* That "security advisory" will also allow us to have a temporary private fork, to work on the fix in confidentiality. | ||
* Once a fix is ready, we will include the fix in our next release and mark that release as a security release. | ||
* Details on the issue will be embargoed for 30 days to give users an oppurtunity to upgrade, after which we will | ||
coordinate disclosure with the researcher(s). | ||
* If you've contributed the fix, you will be credited for it. | ||
|
||
## Policy | ||
|
||
Find out more about our [responsible disclosure policy](https://inditex.responsibledisclosure.com/hc/en-us#vdp_policy) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters