From b6805c54d67f902d32afecc5ca153cd81a77764f Mon Sep 17 00:00:00 2001 From: "W. Felix Handte" Date: Tue, 13 Feb 2024 11:50:55 -0500 Subject: [PATCH 1/2] Add SECURITY.md File This just adds a copy of the Meta default SECURITY.md that we can then modify. --- SECURITY.md | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..4e5f09cbe --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,7 @@ +# Reporting and Fixing Security Issues + +Please do not open GitHub issues or pull requests - this makes the problem immediately visible to everyone, including malicious actors. Security issues in this open source project can be safely reported via the Meta Bug Bounty program: + +https://www.facebook.com/whitehat + +Meta's security team will triage your report and determine whether or not is it eligible for a bounty under our program. From e13d099bf881d69d6cf8bcd5cd4f677e1ce86bea Mon Sep 17 00:00:00 2001 From: "W. Felix Handte" Date: Tue, 13 Feb 2024 11:51:37 -0500 Subject: [PATCH 2/2] Advertise Availability of Security Vulnerability Notifications --- SECURITY.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 4e5f09cbe..a5f9a7e1f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -5,3 +5,11 @@ Please do not open GitHub issues or pull requests - this makes the problem immed https://www.facebook.com/whitehat Meta's security team will triage your report and determine whether or not is it eligible for a bounty under our program. + +# Receiving Vulnerability Notifications + +In the case that a significant security vulnerability is reported to us or discovered by us---without being publicly known---we will, at our discretion, notify high-profile, high-exposure users of Zstandard ahead of our public disclosure of the issue and associated fix. + +If you believe your project would benefit from inclusion in this list, please reach out to one of the maintainers. + +