Skip to content

Latest commit

 

History

History
44 lines (29 loc) · 1.45 KB

SECURITY.md

File metadata and controls

44 lines (29 loc) · 1.45 KB

Security Policy

  1. Reporting security problems to lawndoc
  2. Security Point of Contact
  3. Vulnerability Response Process

Reporting security problems to lawndoc

DO NOT CREATE AN ISSUE to report a security problem. Instead, please send me an email

Security Point of Contact

The security point of contact is myself, C.J. May. I respond to security incident reports as fast as possible, within three business days at the latest.

Incident Response Process

In case a vulnerability is discovered or reported, I will follow the following process to validate, respond, and remediate:

1. Validate

The first step is to find out the root cause, nature and scope of the vulnerability.

  • Prove that the vulnerability can be exploited.
  • Find out knows about the vulnerability and who is affected.
  • Find out what data was potentially exposed.

2. Response

After the initial assessment and containment to my best abilities, I will document all actions taken in a response plan.

I will create a GitHub Security Advisory in this repository to inform users about the incident and what I actions I took to contain it.

3. Remediation

Once the vulnerability is confirmed to be resolved, I will summarize the lessons learned from the incident and create a list of actions I will take to prevent it from happening again.