]> git.smokeofanarchy.ru Git - space-station-14.git/commitdiff
Add SECURITY.md (#14551)
authorVisne <39844191+Visne@users.noreply.github.com>
Thu, 9 Mar 2023 22:01:40 +0000 (23:01 +0100)
committerGitHub <noreply@github.com>
Thu, 9 Mar 2023 22:01:40 +0000 (16:01 -0600)
.github/ISSUE_TEMPLATE/config.yml
SECURITY.md [new file with mode: 0644]

index d9011765aacf4f54f09b6dfbd9eb1b73f4c12697..09c9e76b19301de6a87b08867af2fb578cdf02fd 100644 (file)
@@ -1,7 +1,7 @@
 contact_links:
-  - name: Report a Security Exploit
-    url: https://discord.gg/MwDDf6t
-    about: Please report serious security exploits and vulnerabilities to @PJB3005 (PJB#3005/97089048065097728 on Discord).
+  - name: Report a Security Vulnerability
+    url: https://github.com/space-wizards/space-station-14/blob/master/SECURITY.md
+    about: Please report security vulnerabilities privately so we can fix them before they are publicly disclosed.
   - name: Request a Feature
     url: https://discord.gg/rGvu9hKffJ
     about: Submit feature requests on our Discord server (https://discord.gg/rGvu9hKffJ).
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644 (file)
index 0000000..3819707
--- /dev/null
@@ -0,0 +1,9 @@
+# Reporting a security vulnerability
+You can report a security vulnerability through Discord or through email.
+
+If you want to send an email, you can contact us at <telecommunications@spacestation14.com>.
+If you want to contact us through Discord, you can join [our server](https://discord.gg/MwDDf6t)
+and then **privately** message anyone with the `@Wizard` or `@SS14 Maintainer` role.
+
+In either case, **do not publicly disclose the vulnerability until we explicitly give
+you permission to do so**.