Skip to content

Create SECURITY.md - #10

Open
udhayapraveen wants to merge 1 commit into
haproxytech:mainfrom
udhayapraveen:patch-2
Open

udhayapraveen wants to merge 1 commit into
haproxytech:mainfrom
udhayapraveen:patch-2

Conversation

@udhayapraveen

Copy link
Copy Markdown

Could the project please consider adding a SECURITY.md file to outline how to safely report security vulnerabilities?

zaga00 added a commit that referenced this pull request Sep 18, 2026
A SECURITY.md file was added.  It names the supported release line, the
private advisory form on GitHub as the only reporting channel, the scope
of the policy against the data the filter handles, and the window before
a report may be made public.

The scope follows where the input comes from: the headers, the URL and
the sample expressions carry remote data into the filter, while the two
configurations come from the operator.  Findings in HAProxy itself or in
the wrapper library belong to those projects.

Thanks to udhayapraveen for the idea; the suggestion is in the GitHub
pull request #10.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant