-
Notifications
You must be signed in to change notification settings - Fork 13
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Showing
31 changed files
with
164 additions
and
100 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,25 +1,44 @@ | ||
# Security Policy | ||
|
||
We take security seriously and appreciate your efforts to make Opteryx more secure. | ||
|
||
## Supported Versions | ||
|
||
The head of the current and previous minor version are supported for functional and security fixes. New features are only added to the latest version. Patch versions are not supported, fixes generally require the creation on a new patch version. | ||
We support the current and previous minor versions for functional and security fixes. New features are only added to the latest version, while patch versions are created as needed for critical fixes. | ||
|
||
| Version | Supported | | ||
| ------- | ------------------ | | ||
| 0.7 | :white_check_mark: | | ||
| 0.8 | :white_check_mark: | | ||
| <= 0.6 | :x: | | ||
| 0.18 | ✅ | | ||
| 0.17 | ✅ | | ||
| <= 0.16 | ❌ | | ||
|
||
All features in supported versions have support to resolve security issues regardless, however features which are due for deprecation may be removed rather than fixed. | ||
### Key Notes | ||
|
||
Releases may be yanked from PyPI if they contain material bugs, including security flaws. | ||
- Features due for deprecation may be removed rather than fixed. | ||
- Releases containing material bugs or security vulnerabilities may be yanked from PyPI. | ||
- To stay secure, we recommend using the latest version wherever possible. | ||
|
||
## Reporting a Vulnerability | ||
|
||
Thank you for helping to make Opteryx more secure - Security weaknesses should be reported [via GitHub](https://github.com/mabel-dev/opteryx/security/advisories). | ||
Thank you for helping to keep Opteryx secure! If you’ve discovered a potential vulnerability, please follow these steps: | ||
|
||
1. **Submit a Report**: Vulnerabilities should be reported through [GitHub Security Advisories](https://github.com/mabel-dev/opteryx/security/advisories). | ||
1. **Include Details**: To help us assess the issue quickly, please include: | ||
- A description of the vulnerability | ||
- Steps to reproduce it | ||
- Affected versions | ||
- Any known mitigations | ||
1. **Expectations**: We aim to triage and respond within 7 days. If you haven’t heard back, feel free to follow up. | ||
|
||
### Disclosure Timeline | ||
- We follow a **90-day coordinated disclosure timeline** from the first contact, regardless of resolution status. | ||
- Credit will be given to researchers unless anonymity is requested. | ||
|
||
Please provide a description of the issue, the steps you took to create the issue, affected versions, and if known, mitigations for the issue. | ||
## Scope of Security Issues | ||
|
||
We will try to triage and respond to you within a week, if you do not get a response, please continue to get in touch - we appreciate your input but are a small development team who may not monitor for communications continuously. | ||
This policy covers vulnerabilities that may compromise: | ||
- Data confidentiality, integrity, or availability | ||
- System functionality or integrity | ||
- Compliance with security standards | ||
|
||
This project follows a 90 day disclosure timeline (from first contact) regardless of response or resolution. | ||
We appreciate your cooperation in helping us maintain a secure and reliable system for the Opteryx community. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.