Publish security policy.

This commit is contained in:
David Kocher
2025-01-13 09:29:07 +01:00
parent 3f3892297c
commit a6a863e89a
+25
View File
@@ -0,0 +1,25 @@
# Security Policy
## Supported Versions
Only the [latest](https://cyberduck.io/changelog/) version is supported with security updates.
## Reporting a Vulnerability
We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your
contributions.
To report a security vulnerability, use
the [GitHub Security Advisory feature](https://github.com/iterate-ch/cyberduck/security/advisories). This feature allows
you to privately discuss, fix, and publish information about security vulnerabilities.
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the issue
## Preferred Language
We prefer all communications to be in English.