Skip to content

Commit

Permalink
security.md: add some more text
Browse files Browse the repository at this point in the history
  • Loading branch information
stigtsp authored and Jan Henning Thorsen committed Dec 13, 2021
1 parent 3e2aa14 commit d4609e4
Showing 1 changed file with 8 additions and 3 deletions.
11 changes: 8 additions & 3 deletions SECURITY.md
Expand Up @@ -2,10 +2,15 @@

## Supported Versions

Only the latest version will contain security patches.
Only the latest version of Convos will receive security updates.

## Reporting a Vulnerability

If you know of a vulnerability, then please contact us at [contact@convos.chat](mailto:contact@convos.chat).
If you've found a security issue please contact us privately at [contact@convos.chat](mailto:contact@convos.chat) with a detailed description of the steps required to reproduce the vulnerability (POC scripts, logs and screenshots are very helpful to us).

This will give us some time to make a new release before letting the public know what the issue is.
When we receive a vulnerability report, we would need some time to:
- Confirm the problem and assess severity.
- Check the code to find any potential similar problems.
- Prepare fixes and coordinate a release.

Please allow at least 30 days before disclosure.

0 comments on commit d4609e4

Please sign in to comment.