diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..cf52151 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,15 @@ +# Security Policy + +## Supported Versions + +At any point in time, we only support the latest version of Lookyloo. +There will be no security patches for other releases (tagged or not). + +## Reporting a Vulnerability + +In the case of a security vulnerability report, we ask the reporter to send it directly to +[CIRCL](https://www.circl.lu/contact/), if possible encrypted with the following GnuPG key: +**CA57 2205 C002 4E06 BA70 BE89 EAAD CFFC 22BD 4CD5**. + +If you report security vulnerabilities, do not forget to **tell us if and how you want to +be acknowledged** and if you already requested CVE(s). Otherwise, we will request the CVE(s) directly.