Skip to content

Commit f1eaf4c

Browse files
committed
Update security policy
1 parent 436400d commit f1eaf4c

File tree

1 file changed

+5
-7
lines changed

1 file changed

+5
-7
lines changed

.github/SECURITY.md

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,12 @@
44

55
Only the latest versions of Stack's server and client packages are supported. We do not provide security updates for older versions.
66

7-
## Reporting a Vulnerability
7+
If you would like to get security consulting regarding older versions of on-prem or self-hosted deployments of Stack, please [contact us](mailto:team@stack-auth.com).
88

9-
Stack Auth practices [responsible disclosure](https://en.wikipedia.org/wiki/Coordinated_vulnerability_disclosure).
9+
## Reporting a Vulnerability
1010

11-
Please disclose security vulnerabilities responsibly by emailing us at responsible-disclosure@stack-auth.com. In this case:
11+
Stack Auth practices [responsible disclosure](https://en.wikipedia.org/wiki/Coordinated_vulnerability_disclosure). This helps us protect our users, but requires your cooperation.
1212

13-
- We will get back to you within 96 hours.
14-
- We will aim to get a fix released within 30 days, and disclose the issue, crediting you.
15-
- If we are unable to fix the issue within 90 days, we will disclose the issue publicly.
13+
Please disclose security vulnerabilities responsibly by emailing us at security@stack-auth.com. In this case, we will get back to you within 96 hours, and aim to get a fix released as soon as possible. We will disclose the issue publicly after at most 90 days.
1614

17-
Please do not create GitHub issues with security vulnerabilities; instead, email us directly at the address above.
15+
Hence, we ask you not to publicize issues until the 90 days deadline is over. Also, please do not create GitHub issues with security vulnerabilities; instead, email us directly at the address above.

0 commit comments

Comments
 (0)