Skip to content

Commit 7a497f1

Browse files
committedMay 25, 2024·
Update security policy
1 parent e776417 commit 7a497f1

File tree

1 file changed

+13
-3
lines changed

1 file changed

+13
-3
lines changed
 

‎SECURITY.md

+13-3
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,19 @@
44

55
| Version | Supported |
66
| --------- | ------------------ |
7-
| >= 1.12.x | :white_check_mark: |
8-
| < 1.12.0 | :x: |
7+
| >= 1.13.x | :white_check_mark: |
8+
| < 1.13.0 | :x: |
99

1010
## Reporting a Vulnerability
1111

12-
Please contact security@getformwork.org with an explaination of the security issue you found and we'll work together to resolve it.
12+
We appreciate anyone's effort to report vulnerabilities found in Formwork. Be responsible about disclosing the vulnerability
13+
14+
**You can [draft a security advisory](https://github.com/getformwork/formwork/security/advisories/new)** with an explaination of the security issue you found and we'll work together to resolve it.
15+
16+
If you prefer you can still contact security@getformwork.org
17+
18+
> [!WARNING]
19+
> Remember that not informing about the vulnerability or publicly disclosing details about the vulnerability even on our Discord channels, or without us knowing, which is even worse, exposes Formwork users to unnecessary additional risk.
20+
21+
> [!IMPORTANT]
22+
> Please do NOT use third party security reporting services, or authorities like MITRE to get CVE IDs, we like to keep everything at GitHub for better manageability. We'll request a CVE ID for confirmed vulnerabilities.

0 commit comments

Comments
 (0)
Please sign in to comment.