Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: Create SECURITY.md #1023

Merged
merged 2 commits into from
Mar 29, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Tutor Ethical Vulnerability Disclosure Policy


## Reporting a Vulnerability

To ensure the health of the codebase and the larger Open edX and Tutor communities, please do not create GitHub issues for a security vulnerability. Report any security vulnerabilities or concerns by sending an email to [security.tutor@edly.io](mailto:security.tutor@edly.io). To ensure a timely triage and fix of the security issue, include as many details you can when reporting the vulnerability. Some pieces of information to consider:

* The nature of the vulnerability, e.g.
* Authentication and Authorization
* Data Integrity and Confidentiality
* Security Configurations
* Third-party dependencies
* The impact of the security risk
* A detailed description of the steps necessary to reproduce the issue
* The links to the vulnerable code
* The links to third-party libraries/packages if the vulnerability is present in such a dependency.

## Bug Bounty
Edly/Tutor does not offer a bug bounty for reported vulnerabilities.
Loading