6
0
mirror of https://github.com/ChristianLight/tutor.git synced 2025-01-23 21:48:24 +00:00

docs: Create SECURITY.md (#1023)

* docs: Create SECURITY.md
This commit is contained in:
Syed Muhammad Dawoud Sheraz Ali 2024-03-29 15:48:17 +05:00 committed by GitHub
parent 178104522e
commit 431ddc97fb
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

19
SECURITY.md Normal file
View File

@ -0,0 +1,19 @@
# Tutor Ethical Vulnerability Disclosure Policy
## Reporting a Vulnerability
To ensure the health of the codebase and the larger Open edX and Tutor communities, please do not create GitHub issues for a security vulnerability. Report any security vulnerabilities or concerns by sending an email to [security.tutor@edly.io](mailto:security.tutor@edly.io). To ensure a timely triage and fix of the security issue, include as many details you can when reporting the vulnerability. Some pieces of information to consider:
* The nature of the vulnerability, e.g.
* Authentication and Authorization
* Data Integrity and Confidentiality
* Security Configurations
* Third-party dependencies
* The impact of the security risk
* A detailed description of the steps necessary to reproduce the issue
* The links to the vulnerable code
* The links to third-party libraries/packages if the vulnerability is present in such a dependency.
## Bug Bounty
Edly/Tutor does not offer a bug bounty for reported vulnerabilities.