diff --git a/SECURITY.md b/SECURITY.md index b053c6fdc8..18a848ac1d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,12 +2,13 @@ ## Supported Versions -| Version | Supported | -| -------- | ------------------ | -| Latest | :white_check_mark: | -| Older | :x: | +We only accept security reports against the latest version in this repo or the version deployed to app.diagrams.net, if different. ## Reporting a Vulnerability -Email support@diagrams.net. If you do not wish to submit by email, please -ask for an alternative via email or Github issue. \ No newline at end of file +Report at https://huntr.dev/bounties/disclose?target=https%3A%2F%2Fgithub.com%2Fjgraph%2Fdrawio&validSearch=true. There is a bug bounty program in place there. + +## Out of scope + +- Issues relating to the PlantUML integration. +- Issues relating to the www.drawio.com web site.