forked from Open-CMSIS-Pack/cmsis-toolbox
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
1 changed file
with
34 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,34 @@ | ||
# Open-CMSIS-Pack Security Policy | ||
|
||
This document outlines the security procedures and policies for the Open-CMSIS-Pack cmsis-toolbox project. | ||
|
||
## Table of Contents | ||
- [Reporting a Security Issue](#reporting-a-security-issue) | ||
- [Vulnerability Management](#vulnerability-management) | ||
- [Improving This Policy](#improving-this-policy) | ||
|
||
## Reporting a Security Issue | ||
|
||
The Open-CMSIS-Pack cmsis-toolbox maintainers take security issues seriously and appreciate responsible disclosure. Your efforts to improve project security are highly valued. | ||
|
||
We use GitHub's [private vulnerability reporting](https://docs.github.com/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability). To submit a report, please include: | ||
|
||
- A detailed description of the issue | ||
- Steps to reproduce the vulnerability | ||
- Affected project versions | ||
- Any known mitigations | ||
|
||
A maintainer will acknowledge your report as soon as possible and guide the next steps. We will keep you informed of progress toward a fix and may request additional details if needed. | ||
|
||
## Vulnerability Management | ||
|
||
Once a security issue is reported, the maintainers will: | ||
|
||
1. Confirm the issue | ||
2. Identify affected versions | ||
3. Audit related code for similar vulnerabilities | ||
4. Develop and release patches for maintained versions | ||
|
||
## Improving This Policy | ||
|
||
If you have suggestions for improving this process, please open an issue or submit a pull request. |