Create SECURITY.md for security policy#326
Conversation
Added a security policy document outlining supported versions and vulnerability reporting.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2477b5a09e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| | 5.1.x | :white_check_mark: | | ||
| | 5.0.x | :x: | | ||
| | 4.0.x | :white_check_mark: | | ||
| | < 4.0 | :x: | |
There was a problem hiding this comment.
Align the supported version table with actual releases
This policy declares 5.1.x and 4.0.x as supported security branches even though the package metadata and release manifests in this repo are on 1.0.4, and repo-wide search only finds 1.x release metadata. Once GitHub displays this SECURITY.md, users will be told to expect fixes for non-existent/unsupported release lines while the current 1.x line is not listed as supported, so the table should be replaced with the project's real supported version policy.
Useful? React with 👍 / 👎.
Added a security policy document outlining supported versions and vulnerability reporting.