From 6b461d6482e1b626392e7b1f9485d80be37d4625 Mon Sep 17 00:00:00 2001 From: DavidCarliez Date: Tue, 28 Apr 2026 21:07:48 +0200 Subject: [PATCH] Create SECURITY.md Security policy so security researcher can report vulnerabilities privately and maintainers will be able to use Github CNA to request CVE --- SECURITY.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..076c49be7 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,12 @@ +# Security Policy + +If you believe you've found a security vulnerability in GitNexus, please **do +not open a public issue or pull request**. + +Instead, report it privately via [GitHub Private Vulnerability Reporting](https://github.com/abhigyanpatwari/GitNexus/security/advisories/new), +so the maintainers can review and fix it before details become public. + +Please include reproduction steps and your assessment of the impact. We'll +acknowledge the report and coordinate a fix and disclosure timeline with you. + +Thank you for helping keep GitNexus and its users safe.