Skip to content

Commit fd13c1b

Browse files
h3rrrcoderabbitai[bot]KumoLiuericspodpre-commit-ci[bot]
authored
Create SECURITY.md (#8546)
Help the project add a more detailed VDP (Vulnerability Disclosure Program) description, and request to view the three security vulnerabilities I submitted some time ago: GHSA-x6ww-pf9m-m73m, GHSA-6vm5-6jv9-rjpj, GHSA-p8cm-mm2v-gwjm --------- Signed-off-by: h3rrr <[email protected]> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: YunLiu <[email protected]> Co-authored-by: Eric Kerfoot <[email protected]> Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
1 parent 725c8de commit fd13c1b

File tree

1 file changed

+18
-0
lines changed

1 file changed

+18
-0
lines changed

SECURITY.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
MONAI takes security seriously and appreciate your efforts to responsibly disclose vulnerabilities. If you discover a security issue, please report it as soon as possible.
5+
6+
To report a security issue:
7+
* please use the GitHub Security Advisories tab to "[Open a draft security advisory](https://github.com/Project-MONAI/MONAI/security/advisories/new)".
8+
* Include a detailed description of the issue, steps to reproduce, potential impact, and any possible mitigations.
9+
* If applicable, please also attach proof-of-concept code or screenshots.
10+
* We aim to acknowledge your report within 72 hours and provide a status update as we investigate.
11+
* Please do not create public issues for security-related reports.
12+
13+
## Disclosure Policy
14+
* We follow a coordinated disclosure approach.
15+
* We will not publicly disclose vulnerabilities until a fix has been developed and released.
16+
* Credit will be given to researchers who responsibly disclose vulnerabilities, if requested.
17+
## Acknowledgements
18+
We greatly appreciate contributions from the security community and strive to recognize all researchers who help keep MONAI safe.

0 commit comments

Comments
 (0)