From 1a7ebfc8f0805873d227d5049fe6c4b655817cbb Mon Sep 17 00:00:00 2001 From: Jack Moran <28000676+itz-d0dgy@users.noreply.github.com> Date: Sun, 3 Nov 2024 09:03:38 +1300 Subject: [PATCH] Create SECURITY.md * Create SECURITY.md Co-authored-by: Chocobo1 PR #21589 --- SECURITY.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..6c931a30c --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,18 @@ +# Security Policy + +qBittorrent takes the security of our software seriously, including all source code repositories managed through our GitHub organisation. +If you believe you have found a security vulnerability in qBittorrent, please report it to us as described below. + +## Reporting Security Issues + +Please do not report security vulnerabilities through public GitHub issues. Instead, please use GitHubs private vulnerability reporting functionality associated to this repository. Additionally, you may email us with all security-related inquiries and notifications at `security@qbittorrent.org`. + +Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue: +1. Type of issue +2. Step-by-step instructions to reproduce the issue +3. Proof-of-concept or exploit code (if possible) +4. Potential impact of the issue, including how an attacker might exploit the issue + +This information will help us triage your report more quickly. Any and all CVEs will be requested and issued through GitHubs private vulnerability reporting functionality, which will be published alongside the disclosure. + +This security policy only applies to the most recent stable branch of qBittorrent. Flaws in old versions that are not present in the current stable branch will not be fixed.