Skip to content

Commit 9603d8a

Browse files
authored
Add SECURITY.md (helidon-io#1094)
1 parent 98aba54 commit 9603d8a

File tree

1 file changed

+37
-0
lines changed

1 file changed

+37
-0
lines changed

SECURITY.md

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
# Reporting security vulnerabilities
2+
3+
Oracle values the independent security research community and believes that
4+
responsible disclosure of security vulnerabilities helps us ensure the security
5+
and privacy of all our users.
6+
7+
Please do NOT raise a GitHub Issue to report a security vulnerability. If you
8+
believe you have found a security vulnerability, please submit a report to
9+
[[email protected]][1] preferably with a proof of concept. Please review
10+
some additional information on [how to report security vulnerabilities to Oracle][2].
11+
We encourage people who contact Oracle Security to use email encryption using
12+
[our encryption key][3].
13+
14+
We ask that you do not use other channels or contact the project maintainers
15+
directly.
16+
17+
Non-vulnerability related security issues including ideas for new or improved
18+
security features are welcome on GitHub Issues.
19+
20+
## Security updates, alerts and bulletins
21+
22+
Security updates will be released regularly as part of planned project releases.
23+
If needed this project will release security fixes in conjunction
24+
with the Oracle Critical Patch Update program. Additional information,
25+
including past advisories, is available on the Oracle [security alerts][4] page.
26+
27+
## Security-related information
28+
29+
We will provide security related information such as a threat model, considerations
30+
for secure use, or any known security issues in our documentation. Please note
31+
that labs and sample code are intended to demonstrate a concept and may not be
32+
sufficiently hardened for production use.
33+
34+
[1]: mailto:[email protected]
35+
[2]: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
36+
[3]: https://www.oracle.com/security-alerts/encryptionkey.html
37+
[4]: https://www.oracle.com/security-alerts/

0 commit comments

Comments
 (0)