diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..1a14729 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,19 @@ +# Reporting security vulnerabilities + +Your efforts to responsibly disclose your findings are appreciated. + +** **Please do _not_ report security vulnerabilities through public GitHub issues.** ** + +If you believe you have found a **security vulnerability**, then please report it to security@axllent.org so +your findings can be investigated, and if confirmed, fixed and released in a timely manner. + +Your report should include: + +- Mailpit version +- A vulnerability description +- Reproduction steps (if applicable) +- Any other details you think are likely to be important + +You should receive an initial acknowledgement within 24 hours in most cases, and will kept updated throughout the process. + +With your consent, your contributions will be publicly acknowledged.