Skip to content

Commit 559d228

Browse files
Revise security policy for SharpCoreDB
Updated the security policy to clarify supported versions and reporting process.
1 parent 26f6851 commit 559d228

1 file changed

Lines changed: 33 additions & 0 deletions

File tree

‎SECURITY.md‎

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
Only the **V2 line** of SharpCoreDB is currently supported with security updates.
6+
7+
| Version | Supported |
8+
| ------- | ------------------ |
9+
| 2.x.x | :white_check_mark: |
10+
| < 2.0 | :x: |
11+
12+
## Reporting a Vulnerability
13+
14+
If you discover a security vulnerability in SharpCoreDB, please report it **privately**.
15+
16+
### How to report
17+
Please use GitHub’s private vulnerability reporting feature:
18+
19+
➡️ [Report a vulnerability](https://github.com/MPCoreDeveloper/SharpCoreDB/security/advisories/new)
20+
21+
### What to expect
22+
- We will acknowledge your report A.S.A.P. and within **48 hours**.
23+
- You will receive regular updates on the status of your report (at least once per week).
24+
- If the vulnerability is confirmed:
25+
- We will work on a fix as quickly as possible.
26+
- A security advisory and patched release will be published once the fix is ready.
27+
- If the report is declined, we will explain the reason.
28+
29+
### Scope
30+
- Only vulnerabilities affecting the **V2 line** will be considered.
31+
- Versions below 2.0 are no longer supported and will not receive security updates.
32+
33+
Thank you for helping keep SharpCoreDB secure.

0 commit comments

Comments
 (0)