summaryrefslogtreecommitdiff
path: root/vendor/github.com/microcosm-cc/bluemonday/SECURITY.md
diff options
context:
space:
mode:
Diffstat (limited to 'vendor/github.com/microcosm-cc/bluemonday/SECURITY.md')
-rw-r--r--vendor/github.com/microcosm-cc/bluemonday/SECURITY.md15
1 files changed, 15 insertions, 0 deletions
diff --git a/vendor/github.com/microcosm-cc/bluemonday/SECURITY.md b/vendor/github.com/microcosm-cc/bluemonday/SECURITY.md
new file mode 100644
index 000000000..a344e7c05
--- /dev/null
+++ b/vendor/github.com/microcosm-cc/bluemonday/SECURITY.md
@@ -0,0 +1,15 @@
+# Security Policy
+
+## Supported Versions
+
+Latest tag and tip are supported.
+
+Older tags remain present but changes result in new tags and are not back ported... please verify any issue against the latest tag and tip.
+
+## Reporting a Vulnerability
+
+Email: <bluemonday@buro9.com>
+
+Bluemonday is pure OSS and not maintained by a company. As such there is no bug bounty program but security issues will be taken seriously and resolved as soon as possible.
+
+The maintainer lives in the United Kingdom and whilst the email is monitored expect a reply or ACK when the maintainer is awake.