adding license, code of conduct, templates... etc)
This commit is contained in:
+44
@@ -0,0 +1,44 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
The following versions of OxiCloud are currently supported with security updates:
|
||||
|
||||
| Version | Supported |
|
||||
| ------- | ------------------ |
|
||||
| Latest | :white_check_mark: |
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
The OxiCloud team takes security issues seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.
|
||||
|
||||
To report a security vulnerability, please follow these steps:
|
||||
|
||||
1. **DO NOT** disclose the vulnerability publicly (e.g., in GitHub issues)
|
||||
2. Email details of the vulnerability to the project maintainers
|
||||
3. Include as much information as possible, such as:
|
||||
- A clear description of the vulnerability
|
||||
- Steps to reproduce the issue
|
||||
- Potential impact
|
||||
- Suggested fixes if available
|
||||
|
||||
## What to Expect
|
||||
|
||||
After submitting a vulnerability report, you can expect the following:
|
||||
|
||||
1. **Acknowledgment**: The team will acknowledge receipt of your report within 3 business days
|
||||
2. **Assessment**: We'll evaluate the vulnerability and determine its impact
|
||||
3. **Plan**: We'll develop a plan to address the vulnerability
|
||||
4. **Fix & Release**: Once fixed, we'll release an update
|
||||
5. **Recognition**: With your permission, we'll acknowledge your contribution in the release notes
|
||||
|
||||
## Security Best Practices for OxiCloud Users
|
||||
|
||||
- Keep your OxiCloud installation updated to the latest version
|
||||
- Use strong, unique passwords for all user accounts
|
||||
- Configure proper file permissions
|
||||
- Regularly back up your data
|
||||
- Consider running OxiCloud behind a reverse proxy with HTTPS
|
||||
- Implement IP restrictions where appropriate
|
||||
|
||||
Thank you for helping keep OxiCloud and its users secure!
|
||||
Reference in New Issue
Block a user