Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 2 additions & 9 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,16 +6,13 @@ If you discover a security vulnerability in this project, please report it to us

Please **do not** disclose the vulnerability publicly until we have had a chance to investigate and address it.

To report a vulnerability, please email us at:
[insert contact email or secure communication method]

If you prefer a different communication method, please let us know, and we will accommodate it.
To report a vulnerability, please use our [disclosure submission program](https://vdp.inditex.com).

## Security Updates

We are committed to fixing any security vulnerabilities discovered in the project. Once a report is received, we will:

1. Acknowledge the report within [insert timeframe, e.g., 48 hours].
1. Acknowledge the report within 48 hours.
2. Work to resolve the issue and release an appropriate patch.
3. Publicly disclose the details of the fix once it is available, while following responsible disclosure practices.

Expand All @@ -36,7 +33,3 @@ We recommend that contributors follow these security best practices when develop

As part of the responsibility for maintaining a secure environment, we ask that all contributors adhere to the project's Code of Conduct, ensuring that contributions do not introduce security risks or malicious behavior into the project.

## Attribution

This Security Policy is inspired by the [GitHub Security Policy Template](https://docs.github.com/en/github/managing-security-vulnerabilities/creating-a-security-policy) and other open-source best practices.