diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..e28984b03 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,12 @@ +# Security Policy + +## Supported Versions + +We only make security updates to the latest MAJOR.MINOR version of the project. No securit updates are backported to previous versions. If you +want be up to date on security patches, make sure your Plausible image is up to date with `plausible/analytics:latest` + +## Reporting a Vulnerability + +If you've found a security vulnerability with the Plausible codebase, you can disclose it responsibly by sending a summary to security@plausible.io. +We will review the potential threat and fix it as fast as we can. We are incredibly thankful for people who disclose vulnerabilities, unfortunately we do not +have a bounty program in place yet.