From 73b76a5f629b6ef9ce68db585e111d501bee0d08 Mon Sep 17 00:00:00 2001 From: Matthias Kerbl <33470003+MatthiasKerbl@users.noreply.github.com> Date: Fri, 20 Sep 2024 13:57:17 +0200 Subject: [PATCH] Update SECURITY.md --- SECURITY.md | 34 +++++++++++++++++++++------------- 1 file changed, 21 insertions(+), 13 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 034e848..76ad914 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,20 +2,28 @@ ## Supported Versions -Use this section to tell people about which versions of your project are -currently being supported with security updates. - -| Version | Supported | -| ------- | ------------------ | -| 5.1.x | :white_check_mark: | -| 5.0.x | :x: | -| 4.0.x | :white_check_mark: | -| < 4.0 | :x: | +We release security updates for the latest version of **AlDente** here: https://github.com/AppHouseKitchen/AlDente-Charge-Limiter/releases ## Reporting a Vulnerability -Use this section to tell people how to report a vulnerability. +We take the security of our software seriously. If you discover a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner. -Tell them where to go, how often they can expect to get an update on a -reported vulnerability, what to expect if the vulnerability is accepted or -declined, etc. +**How to Report** + +- **Email:** Please send an email to [security@apphousekitchen.com](mailto:security@apphousekitchen.com). +- **Subject Line:** Use a clear and descriptive subject line, such as "Security Vulnerability in AlDente-Charge-Limiter". +- **Content:** Provide a detailed description of the vulnerability, including steps to reproduce it, the potential impact, and any suggested fixes. + +**What to Expect** + +- **Acknowledgment:** We will acknowledge receipt of your report within 48 hours. +- **Investigation:** Our team will investigate the issue and work on a fix. +- **Updates:** We will keep you informed about the progress of the investigation and remediation. +- **Disclosure:** Once the vulnerability is resolved, we will issue a patch and publicly disclose the issue, crediting you for the discovery if you wish. + +**Guidelines** + +- **Confidentiality:** Please do not disclose the vulnerability publicly until we have addressed it. +- **Legal:** You must not violate any laws or breach any agreements in the course of discovering and reporting vulnerabilities. + +Thank you for helping us keep **AlDente** safe and secure for everyone!