mirror of
https://github.com/quickwit-oss/tantivy.git
synced 2026-08-18 12:08:22 +00:00
Merge pull request #3041 from quickwit-oss/cose-sync-security-policy-20260813224347
chore: sync security-policy
This commit is contained in:
+23
@@ -0,0 +1,23 @@
|
||||
# Security Policy
|
||||
|
||||
## Vulnerability Reporting
|
||||
|
||||
We deeply appreciate any effort to discover and disclose security vulnerabilities responsibly.
|
||||
|
||||
### Tantivy CI
|
||||
|
||||
If you would like to report a vulnerability in Tantivy's CI or have security concerns with other Datadog products, please email [security@datadoghq.com](mailto:security@datadoghq.com).
|
||||
|
||||
We take all disclosures seriously and will do our best to respond promptly, verify the vulnerability, and take the necessary steps to fix it. After our initial reply, we will periodically update you on the status of the fix.
|
||||
|
||||
### Other Reports
|
||||
|
||||
Tantivy is an open source project. Users are responsible for managing the environments where they deploy or integrate it. Vulnerabilities in those environments could potentially be exploited by malicious actors who already have access to the user's infrastructure. We encourage responsible disclosure by emailing [security@datadoghq.com](mailto:security@datadoghq.com) so that risks can be properly assessed and mitigated.
|
||||
|
||||
To help us investigate your report, please include any of the following:
|
||||
|
||||
- A proof of concept
|
||||
- Any tools used, including their versions
|
||||
- Any relevant output
|
||||
|
||||
Do not include credentials, secrets, or other sensitive information in a public GitHub issue.
|
||||
Reference in New Issue
Block a user