Skip to content

Commit

Permalink
Create SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
KirillKurdyukov authored Jan 23, 2024
1 parent 1f47a1c commit a0281e1
Showing 1 changed file with 26 additions and 0 deletions.
26 changes: 26 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Security Policy

## Reporting a Vulnerability

We're extremely grateful for security researchers and users who report vulnerabilities they discovered in YDB. All reports are thoroughly investigated.

To report a potential vulnerability in YDB please email details to [[email protected]](mailto:[email protected]).

### When Should I Report a Vulnerability?

- You think you discovered a potential security vulnerability in YDB
- You are unsure how a vulnerability affects YDB

## Security Vulnerability Response

Each report is acknowledged and analyzed by YDB maintainers within 5 working days.
We will keep the reporter informed about the issue progress.

## Public Disclosure Timing

A public disclosure date is negotiated by YDB maintainers and the bug submitter.
We prefer to fully disclose the bug as soon as possible once a mitigation is available for YDB users.
It is reasonable to delay disclosure when the bug or the fix is not yet fully understood,
the solution is not well-tested, or for vendor coordination.
The timeframe for disclosure is from immediate (especially if it's already publicly known) to 90 days.
For a vulnerability with a straightforward mitigation, we expect report date to disclosure date to be on the order of 7 days.

0 comments on commit a0281e1

Please sign in to comment.