From 78bd4960b7f16c512045e478479aad08c9e1f617 Mon Sep 17 00:00:00 2001 From: JordanNewell <58616955+JordanNewell@users.noreply.github.com> Date: Sat, 26 Sep 2026 15:47:00 -0400 Subject: [PATCH] Add SECURITY.md security policy --- SECURITY.md | 63 +++++++++++++++++++++++++++++++++++------------------ 1 file changed, 42 insertions(+), 21 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index dba414e..898a86d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,39 +1,60 @@ # Security Policy -## Supported versions +## Reporting a Vulnerability -Only the latest release receives security updates. +**Do not open a public GitHub issue for a security vulnerability.** -## Reporting a vulnerability +Report vulnerabilities privately to ****. +(Placeholder address — Jordan will replace with a dedicated security inbox.) -Email **security@jordannewell.com** with: +If you have a PGP key, encrypt the report. The fingerprint of the project's +reporting key will be published here once Jordan generates it: -- A description of the issue and its impact -- Reproduction steps (a minimal example is ideal) -- Affected version — run `temporal-git --version` +``` +PGP fingerprint: TBD (to be published) +PGP public key: TBD (to be published) +``` -**Do not open a public GitHub issue** for security reports. +Until the PGP key is published, plaintext email is fine — but please prefer +it over GitHub issues either way. -## Response timeline +Please include, where possible: -- **Acknowledgment:** within 72 hours -- **Initial assessment:** within 5 business days -- **Fix or mitigation:** target 30 days for high-severity issues +- A description of the issue and its impact. +- The smallest reproducer you can manage (a failing test is ideal). +- Affected versions (or the commit SHA you tested against). +- Any mitigations you've already tried. -Please refrain from public disclosure until a fix has been published, to -protect downstream users. Reporters will be credited in the release notes -unless they prefer otherwise. +## Response SLA + +- **Acknowledgement:** within **48 hours** (typically same business day). +- **Initial assessment + severity rating:** within **5 business days**. +- **Fix or mitigation timeline** depends on severity: + - *Critical* (RCE, key compromise, auth bypass): patch or mitigation + within 7 days of confirmation; coordinated disclosure afterwards. + - *High*: patch within 30 days. + - *Medium / Low:* next minor release. + +We will keep you informed at each step and credit you in the release notes +unless you'd prefer to remain anonymous. ## Scope **In scope:** -- The CLI itself (`temporal-git` and its subcommands) -- The git-bisect automation logic -- The VS Code extension code +- The `temporal-git` tooling: history rewriting, snapshot, and restore logic. +- Anything that could corrupt repository history or leak commit content. **Out of scope:** -- git itself — report upstream -- VS Code — report to Microsoft -- Dependencies — report upstream \ No newline at end of file +- Vulnerabilities in third-party dependencies. Report those upstream. +- Attacks requiring a compromised maintainer, a compromised signing key, or + physical access to the reporter's machine. +- Reports from automated scanners without a working reproducer. + +## Disclosure policy + +We follow **coordinated disclosure**. Once a fix is available we'll publish a +GitHub Security Advisory, request a CVE if appropriate, cut a patch release, +and credit the reporter in the changelog. We will not publish details of +unpatched critical issues.