Create SECURITY.md

Security policy so security researcher can report vulnerabilities privately and maintainers will be able to use Github CNA to request CVE
This commit is contained in:
DavidCarliez 2026-04-28 21:07:48 +02:00 • committed by GitHub
parent dafda284bc
commit 6b461d6482
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

12
SECURITY.md Normal file
View file

@ -0,0 +1,12 @@
# Security Policy
If you believe you've found a security vulnerability in GitNexus, please **do
not open a public issue or pull request**.
Instead, report it privately via [GitHub Private Vulnerability Reporting](https://github.com/abhigyanpatwari/GitNexus/security/advisories/new),
so the maintainers can review and fix it before details become public.
Please include reproduction steps and your assessment of the impact. We'll
acknowledge the report and coordinate a fix and disclosure timeline with you.
Thank you for helping keep GitNexus and its users safe.