Create SECURITY.md for security policyhttps://didactic-orbit-5v4wvvwp… - #936
Create SECURITY.md for security policyhttps://didactic-orbit-5v4wvvwp…#936gcours85-code wants to merge 1 commit into
Conversation
…vj66cp6rx-37083.app.github.dev/ Added a security policy document outlining supported versions and vulnerability reporting guidelines.
gcours85-code
left a comment
There was a problem hiding this comment.
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CAN-1900-0001",
"assignerOrgId": "00000000-0000-4000-9000-000000000000",
"requesterUserId": "00000000-0000-4000-9000-000000000000",
"serial": 1,
"state": "PUBLISHED"
},
"containers": {
"cna": {
"x_theConversation": [
{
"authorRole": "CNA-LR",
"visibility": "public"
}
],
"x_Read_Landing": {
"x_Acknowledge": "NO"
},
"x_Other_CNA": {
"x_CNA_Contact": "IN-CNA-LR-SCOPE"
},
"x_Request_Type": {
"x_Publication_Request": "NO"
},
"x_domain": "",
"providerMetadata": {
"orgId": "00000000-0000-4000-9000-000000000000"
},
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "incorrect input validation"
}
]
}
],
"affected": [
{
"x_CopyOfCNAUnderAffected": "IN-CNA-LR-SCOPE",
"vendor": "v",
"product": "p",
"versions": [
{
"status": "affected",
"version": "1.0"
}
],
"defaultStatus": "unaffected"
}
],
"descriptions": [
{
"lang": "en",
"value": "supplier/product/version is affected by vulnerability type/root cause/impact.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "supplier/product/version is affected by vulnerability type/root cause/impact."
}
]
}
],
"references": [
{
"url": "https://example.com"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV4_0": {
"version": "4.0",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"subAvailabilityImpact": "HIGH",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"baseSeverity": "CRITICAL",
"baseScore": 10,
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
}
}
…vj66cp6rx-37083.app.github.dev/
Added a security policy document outlining supported versions and vulnerability reporting guidelines.