Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Security Policy

## Supported Versions

Use this section to tell people about which versions of your project are
currently being supported with security updates.

| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
| 5.0.x | :x: |
| 4.0.x | :white_check_mark: |
| < 4.0 | :x: |
Comment on lines +8 to +13
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The versions listed in the support table appear to be examples and do not seem to align with the project's current state as described in the README.md. Please update this table to reflect the actual versions of the project and their support status. If no official versions have been released yet, it would be clearer to state that or prepare the table for upcoming releases (e.g., 1.0.x).


## Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.
Comment on lines +17 to +21
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

This section contains placeholder text and lacks the essential information for reporting a vulnerability. It's critical to provide a clear, private channel for security researchers to report issues. You should replace this with concrete instructions, including where to report, expected response times, and the process for handling confirmed vulnerabilities. Using GitHub's private vulnerability reporting feature is a recommended practice.

Suggested change
Use this section to tell people how to report a vulnerability.
Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.
We take all security vulnerabilities seriously. To report a security issue, please use the **[Private Vulnerability Reporting](https://github.com/google/androidify/security/advisories/new)** feature on GitHub.
### Our Commitment
We will make every effort to acknowledge your report within 48 hours. You can expect a more detailed response within 72 hours, indicating the next steps in handling your report. We appreciate your efforts to disclose your findings responsibly and will credit you for your discovery unless you prefer to remain anonymous.