summaryrefslogtreecommitdiff
path: root/SECURITY.md
diff options
context:
space:
mode:
authorMike Vink <mike@pionative.com>2025-02-03 21:29:42 +0100
committerMike Vink <mike@pionative.com>2025-02-03 21:29:42 +0100
commit5155816b7b925dec5d5feb1568b1d7ceb00938b9 (patch)
treedeca28ea15e79f6f804c3d90d2ba757881638af5 /SECURITY.md
fetch tarballHEADmaster
Diffstat (limited to 'SECURITY.md')
-rw-r--r--SECURITY.md21
1 files changed, 21 insertions, 0 deletions
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..de2b983
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,21 @@
+# Security Policy
+
+## Supported Versions
+
+The LuaRocks project supports the _latest version_ of the tool
+for bugfixes and security updates. In other words, if an
+issue is reported and we produce a fix, it will appear in a subsequent
+patch version (x.y.Z) of the tool, but we do not backport fixes
+to previous minor (x.Y.z) or major (X.y.z) versions.
+
+## Reporting a Vulnerability
+
+To report a vulnerability on the LuaRocks CLI tool, email
+Hisham Muhammad at hisham@luarocks.org.
+
+To report a vulnerability on the https://luarocks.org website,
+email Leaf Corcoran at leafot@gmail.com.
+
+We will acknowledge your contact as soon as the message is
+received, then assess the vulnerability and get back to you
+with further feedback once analysis on our end is done.