diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000000000000000000000000000000000000..9dc768a6f5f6c14365774064e2d4b49c696cca80 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,15 @@ +<!-- +SPDX-FileCopyrightText: 2022 FIT-Connect contributors + +SPDX-License-Identifier: EUPL-1.2 +--> + +# Security Vulnerabilities + +Our team is trying to make sure that our code is secure. Nevertheless, we are very grateful for anyone who finds a security vulnerability and reports it to us. + +Please do not report security vulnerabilities through GitLab directly. Because GitLab issues are public, this could result in directly disclosing the vulnerability. + +Please send any request regarding a potential security vulnerability with all the information that could help to `it-sicherheit <at> fitko.de`. See our [security.txt](https://www.fitko.de/.well-known/security.txt) for details. + +If possible please note the release version or the commit id of the main branch that you have investigated.