From 08bfdf13b264af17991e72e351fbc93639103d83 Mon Sep 17 00:00:00 2001 From: Oleksandr <98953475+Oleksandr1414@users.noreply.github.com> Date: Wed, 22 Jul 2026 18:02:27 +0300 Subject: [PATCH] Create SECURITY.md --- SECURITY.md | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..66b3e06a --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,46 @@ +# Security Policy + +Thank you for helping improve the security of sama-server project. + +## Supported Versions + +Only the latest stable release is supported with security updates. + +| Version | Supported | +|---------|-----------| +| Latest release | ✅ | +| Older releases | ❌ | + +## Reporting a Vulnerability + +If you believe you have found a security vulnerability, **please do not create a public GitHub issue**. + +Instead, report it privately by contacting the maintainer: + +- Email: khomenkoigor@gmail.com + +Please include as much information as possible: + +- A description of the vulnerability +- Steps to reproduce +- Expected and actual behavior +- Potential impact +- Proof of concept (if applicable) + +## Response Process + +After receiving your report, we will: + +1. Investigate and validate the report. +2. Work on a fix if the issue is confirmed. + +## Scope + +This policy applies to: + +- Source code in this repository +- GitHub Actions workflows +- Build scripts +- Configuration files + +Third-party dependencies should be reported to their respective maintainers unless the vulnerability results from this project.