Skip to content

Commit

Permalink
Add security.md (#201)
Browse files Browse the repository at this point in the history
  • Loading branch information
anakinxc authored Jan 11, 2024
1 parent 89b756d commit a944d80
Showing 1 changed file with 31 additions and 0 deletions.
31 changes: 31 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Security

If you believe you have found a security vulnerability in any SecretFlow repository that meets
[SecretFlow's definition of a security vulnerability](https://security.alipay.com/announcement.htm?id=1), please report it to us as described below.

## Reporting Security Issues

**Please do not report security vulnerabilities through public GitHub issues.**

Instead, please report them to the ANT GROUP SECURITY Response Center at [https://security.alipay.com/](https://security.alipay.com/).

If you prefer to submit without logging in, send email to [[email protected]](mailto:[email protected]).

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
Additional information can be found at [https://security.alipay.com/](https://security.alipay.com/).

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

* Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
* Full paths of source file(s) related to the manifestation of the issue
* The location of the affected source code (tag/branch/commit or direct URL)
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.

## Preferred Languages

We prefer all communications to be in Chinese or English.

0 comments on commit a944d80

Please sign in to comment.