瀏覽代碼

Set up a security policy

Signed-off-by: Ruben Barkow-Kuder <github@r.z11.de>
tags/v19.0.0beta1
Ruben Barkow 4 年之前
父節點
當前提交
be506f7b29
沒有連結到貢獻者的電子郵件帳戶。
共有 3 個檔案被更改,包括 27 行新增0 行删除
  1. 25
    0
      SECURITY.md
  2. 1
    0
      apps/updatenotification/Makefile
  3. 1
    0
      build/files-checker.php

+ 25
- 0
SECURITY.md 查看文件

@@ -0,0 +1,25 @@
# Security Policy

## Supported Versions

The latest three major release versions of Nextcloud are currently being supported with security updates.
Please visit https://github.com/nextcloud/server/wiki/Maintenance-and-Release-Schedule for further details.

## Reporting a Vulnerability

Security is very important to us. If you have discovered a security issue with Nextcloud,
please read our responsible disclosure guidelines and contact us at [hackerone.com/nextcloud](https://hackerone.com/nextcloud).
Your report should include:

- Product version
- A vulnerability description
- Reproduction steps

A member of the security team will confirm the vulnerability, determine its impact, and develop a fix.
The fix will be applied to the master branch, tested, and packaged in the next security release.
The vulnerability will be publicly announced after the release. Finally, your name will be added
to the [hall of fame](https://hackerone.com/nextcloud/thanks) as a thank you from the entire Nextcloud community. Note our
[threat model](https://nextcloud.com/security/threat-model) to know what is expected behavior.


Please visit https://nextcloud.com/security/ for further information about security.

+ 1
- 0
apps/updatenotification/Makefile 查看文件

@@ -44,6 +44,7 @@ package: clean build-js-production
--exclude=/CONTRIBUTING.md \
--exclude=/issue_template.md \
--exclude=/README.md \
--exclude=/SECURITY.md \
--exclude=/.gitignore \
--exclude=/.scrutinizer.yml \
--exclude=/.travis.yml \

+ 1
- 0
build/files-checker.php 查看文件

@@ -73,6 +73,7 @@ $expectedFiles = [
'remote.php',
'resources',
'robots.txt',
'SECURITY.md',
'status.php',
'tests',
'themes',

Loading…
取消
儲存