Skip to content

Commit 2accad4

Browse files
authored
Merge pull request #45 from hyperledger-best-practice-audit/master
Add default SECURITY policy
2 parents 54fe3e2 + d16bbd3 commit 2accad4

File tree

1 file changed

+23
-0
lines changed

1 file changed

+23
-0
lines changed

SECURITY.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Hyperledger Security Policy
2+
3+
## Reporting a Security Bug
4+
5+
If you think you have discovered a security issue in any of the Hyperledger
6+
projects, we'd love to hear from you. We will take all security bugs
7+
seriously and if confirmed upon investigation we will patch it within a
8+
reasonable amount of time and release a public security bulletin discussing
9+
the impact and credit the discoverer.
10+
11+
There are two ways to report a security bug. The easiest is to email a
12+
description of the flaw and any related information (e.g. reproduction
13+
steps, version) to
14+
[security at hyperledger dot org](mailto:[email protected]).
15+
16+
The other way is to file a confidential security bug in our
17+
[JIRA bug tracking system](https://jira.hyperledger.org).
18+
Be sure to set the “Security Level” to “Security issue”.
19+
20+
The process by which the Hyperledger Security Team handles security bugs
21+
is documented further in our
22+
[Defect Response](https://wiki.hyperledger.org/display/HYP/Defect+Response)
23+
page on our [wiki](https://wiki.hyperledger.org).

0 commit comments

Comments
 (0)