* chore: create security policy Signed-off-by: Joyce Brum <joycebrumu.u@gmail.com> * chore: only latest release on security police Signed-off-by: Joyce Brum <joycebrumu.u@gmail.com> * chore: security policy support on effort base Signed-off-by: Joyce Brum <joycebrumu.u@gmail.com> * Use dedicated e-mail address for security reporting Signed-off-by: Joyce Brum <joycebrumu.u@gmail.com> Co-authored-by: Philip Hyunsu Cho <chohyu01@cs.washington.edu>
23 lines
879 B
Markdown
23 lines
879 B
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
<!-- Use this section to tell people about which versions of your project are
|
|
currently being supported with security updates. -->
|
|
Security updates are applied only to the most recent release.
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
<!-- Use this section to tell people how to report a vulnerability.
|
|
|
|
Tell them where to go, how often they can expect to get an update on a
|
|
reported vulnerability, what to expect if the vulnerability is accepted or
|
|
declined, etc. -->
|
|
|
|
To report a security issue, please email
|
|
[security@xgboost-ci.net](mailto:security@xgboost-ci.net)
|
|
with a description of the issue, the steps you took to create the issue,
|
|
affected versions, and, if known, mitigations for the issue.
|
|
|
|
All support will be made on the best effort base, so please indicate the "urgency level" of the vulnerability as Critical, High, Medium or Low.
|