Add public issue and contribution guidance
This commit is contained in:
+19
@@ -0,0 +1,19 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
Do not report suspected vulnerabilities through a public issue, pull request, discussion, or comment.
|
||||
|
||||
Email **jason@christit.com** with the subject "Dark Mode by GracePress security report".
|
||||
|
||||
Include the affected version, a concise description, reproduction details, potential impact, and any suggested mitigation. Do not include credentials, private keys, customer data, or unrelated private information.
|
||||
|
||||
You should receive an acknowledgement as soon as practical. Please allow time to investigate and prepare a correction before publishing details.
|
||||
|
||||
## Supported versions
|
||||
|
||||
Dark Mode by GracePress is currently in public-development preparation. Version 5.0.0 is planned as the first supported public release. Security reports concerning the current main branch and version 4.8.18 preparation work are still welcome.
|
||||
|
||||
## Scope
|
||||
|
||||
Reports should concern the source in this repository. GracePress Central Hub and OmniLog are separate optional projects and should be reported to their own maintainers when the issue does not originate in Dark Mode by GracePress.
|
||||
Reference in New Issue
Block a user