Added SECURITY.md

Signed-off-by: Janos SUTO <sj@acts.hu>
This commit is contained in:
Janos SUTO 2020-04-21 20:34:29 +02:00
parent 12fbf83455
commit 4b353afa7a

19
SECURITY.md Normal file
View File

@ -0,0 +1,19 @@
Disclosure policy
If you find a security issue, please contact the project owner at sj@acts.hu
with the details (ie. piler version, details of the setup, how to exploit the
vulnerability, etc).
Please provide 30 days for verifying the vulnerability, fixing the issue, and
notifying the piler users.
Security update policy
If a security vulnerability has found, the details, possible mitigations,
workarounds, etc. will be shared on the piler mailing list (piler-user@list.acts.hu)
and on the wiki: http://www.mailpiler.org/
Security configurations
- Use https for the GUI
- Reset the default passwords for admin and auditor