Browse Source

SECURITY.md: Add instructions for reporting security issues

Fixes Issues like https://github.com/agherzan/meta-raspberrypi/pull/1390#issuecomment-2522661895

Signed-off-by: Khem Raj <raj.khem@gmail.com>
Khem Raj 5 months ago
parent
commit
a2f8a64bc6
1 changed files with 20 additions and 0 deletions
  1. 20 0
      SECURITY.md

+ 20 - 0
SECURITY.md

@@ -0,0 +1,20 @@
+How to Report a Potential Vulnerability?
+========================================
+
+If you would like to report a public issue (for example, one with a released
+CVE number), please report it via GitHub issues:
+
+  https://github.com/agherzan/meta-raspberrypi/issues/new/choose
+
+If you are dealing with a not-yet released or urgent issue, please send a
+message to one of the maintainers listed in the [README.md](https://github.com/agherzan/meta-raspberrypi/blob/master/README.md).  Include as many
+details as possible:
+  - the layer or software module affected
+  - the recipe and its version
+  - any example code, if available
+
+Branches maintained with security fixes
+---------------------------------------
+
+See https://wiki.yoctoproject.org/wiki/Releases for the list of current
+releases.  We only accept patches for the LTS releases and the master branch.