summaryrefslogtreecommitdiff
path: root/home/.oh-my-zsh/SECURITY.md
diff options
context:
space:
mode:
authornavewindre <boneyaard@gmail.com>2025-07-13 06:42:05 +0200
committernavewindre <boneyaard@gmail.com>2025-07-13 06:42:05 +0200
commit02f14a9cb152561a5e44062aac79f3b700403b40 (patch)
tree2db8ebda3b7f6f8777783aeb5c60018e6e1359d8 /home/.oh-my-zsh/SECURITY.md
parentcbbdeb2f6b40a102a829f0c47cff052937231f00 (diff)
omz
Diffstat (limited to 'home/.oh-my-zsh/SECURITY.md')
-rw-r--r--home/.oh-my-zsh/SECURITY.md23
1 files changed, 23 insertions, 0 deletions
diff --git a/home/.oh-my-zsh/SECURITY.md b/home/.oh-my-zsh/SECURITY.md
new file mode 100644
index 0000000..f823584
--- /dev/null
+++ b/home/.oh-my-zsh/SECURITY.md
@@ -0,0 +1,23 @@
+# Security Policy
+
+## Supported Versions
+
+At the moment Oh My Zsh only considers the very latest commit to be supported.
+We combine that with our fast response to incidents and the automated updates
+to minimize the time between vulnerability publication and patch release.
+
+| Version | Supported |
+|:-------------- |:------------------ |
+| master | :white_check_mark: |
+| other commits | :x: |
+
+In the near future we will introduce versioning, so expect this section to change.
+
+## Reporting a Vulnerability
+
+**Do not submit an issue or pull request**: this might reveal the vulnerability.
+
+Instead, you should use the form to [privately report a vulnerability to us via GitHub](https://github.com/ohmyzsh/ohmyzsh/security/advisories/new)
+or email the maintainers directly at: [**security@ohmyz.sh**](mailto:security@ohmyz.sh).
+
+We will deal with the vulnerability privately and submit a patch as soon as possible.