Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SECURITY.md #172

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 26 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,29 @@
Please use https://g.co/vulnz to report security vulnerabilities.
# Security Policy

We use https://g.co/vulnz for our intake and triage. For valid issues we will do coordination and disclosure here on
GitHub (including using a GitHub Security Advisory when necessary).
## Reporting a Vulnerability

The Google Security Team will process your report within a day, and respond within a week (although it will depend on the severity of your report).
Please use [https://g.co/vulnz](https://g.co/vulnz) to report security vulnerabilities.

We use [https://g.co/vulnz](https://g.co/vulnz) for our intake and triage. For valid issues, we will do coordination and disclosure here on GitHub (including using a GitHub Security Advisory when necessary).

## Contact Information

If you need to contact the Google Security Team directly, you can reach us at security@google.com.

## Disclosure Policy

The Google Security Team will process your report within a day and respond within a week (although it will depend on the severity of your report).

## Types of Vulnerabilities

Please report any security vulnerabilities that could potentially impact the security of our users or infrastructure.

## Encrypting Sensitive Information

If you need to send sensitive information, please use our PGP key, available at [https://example.com/pgp-key](https://example.com/pgp-key).

## Response Timeline

- Initial acknowledgment: 1 day
- Triage and assessment: 1 week
- Fix and disclosure: Depending on the severity, typically within 30-90 days.