Skip to content

Commit

Permalink
Merge pull request #5 from Dafnik/add-security-notice
Browse files Browse the repository at this point in the history
feat: add SECURITY.md
  • Loading branch information
Dafnik authored Apr 10, 2023
2 parents d35719d + 26b0044 commit 4ffd728
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Security Policy

## Supported Versions

| Version | Supported |
| ------- | ------------------ |
| 1.x.x | :white_check_mark: |
| < 1.0 | :x: |

## Reporting a Vulnerability

If you believe you've identified a security vulnerability in setup-node-pnpm (a bug that allows something to happen that shouldn't be possible), you can reach us at <[email protected]>.

You should _not_ report such issues on GitHub or in other public spaces to give us time to publish a fix for the issue without exposing setup-node-pnpm's users to increased risk.

## Scope

A "vulnerability in setup-node-pnpm" is a vulnerability in the code distributed through our main source code repository on GitHub. Vulnerabilities that are specific to a given installation (e.g. misconfiguration) should be reported to the owner of that installation and not us.

0 comments on commit 4ffd728

Please sign in to comment.