Skip to content

Commit

Permalink
Add initial SECURITY.md policy
Browse files Browse the repository at this point in the history
  • Loading branch information
slyon authored and daniloegea committed Jun 12, 2024
1 parent 44b2a5c commit 56bcb5d
Showing 1 changed file with 16 additions and 0 deletions.
16 changes: 16 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Security Policy

## Supported Versions

We generally support Netplan versions that are being used by the latest Ubuntu LTS and newer.
Please see [Launchpad.net](https://launchpad.net/ubuntu/+source/netplan.io) for the specific version numbers.

## Security best practices

Netplan is a system component that is supposed to be driven as root. Its configuration might contain secret information such as WiFi passwords or VPN credentials, so it's recommended to keep the file permissions for Netplan's configuration very tight, as described in our [threat model](https://netplan.readthedocs.io/en/latest/security/).

## Reporting a Vulnerability

To report a security issue, please email <[email protected]> with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue.

Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed to be a vulnerability, we will assign a CVE. This project follows a maximum disclosure timeline of 90 days.

0 comments on commit 56bcb5d

Please sign in to comment.