diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..9e44b7e3c --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,22 @@ +# Security Policy + +## Supported Versions + + +Security updates are applied only to the most recent release. + +## Reporting a Vulnerability + + + +To report a security issue, please email +[security@xgboost-ci.net](mailto:security@xgboost-ci.net) +with a description of the issue, the steps you took to create the issue, +affected versions, and, if known, mitigations for the issue. + +All support will be made on the best effort base, so please indicate the "urgency level" of the vulnerability as Critical, High, Medium or Low.