Skip to content

Commit ae6a628

Browse files
authored
Create SECURITY.md (#3818)
1 parent 05f4dbb commit ae6a628

File tree

1 file changed

+45
-0
lines changed

1 file changed

+45
-0
lines changed

SECURITY.md

+45
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# Security Policy
2+
3+
As a U.S. Government agency, the General Services Administration (GSA) takes
4+
seriously our responsibility to protect the public's information, including
5+
financial and personal information, from unwarranted disclosure.
6+
7+
## Reporting a Vulnerability
8+
9+
Services operated by the U.S. General Services Administration (GSA)
10+
are covered by the **GSA Vulnerability Disclosure Program (VDP)**.
11+
12+
See the [GSA Vulnerability Disclosure Policy](https://gsa.gov/vulnerability-disclosure-policy)
13+
at <https://www.gsa.gov/vulnerability-disclosure-policy> for details including:
14+
15+
* How to submit a report if you believe you have discovered a vulnerability.
16+
* GSA's coordinated disclosure policy.
17+
* Information on how you may conduct security research on GSA developed
18+
software and systems.
19+
* Important legal and policy guidance.
20+
21+
### [Bug Bounties](https://hackerone.com/gsa_bbp)
22+
23+
Certain GSA/TTS programs have bug bounties that are not discussed at the above link. If you find security issues for any of the following domains:
24+
25+
* cloud.gov
26+
* search.gov
27+
* usa.gov
28+
* 18f.gov
29+
* fedramp.gov
30+
* login.gov
31+
* vote.gov
32+
33+
you should also review the [GSA Bug Bounty program](https://hackerone.com/gsa_bbp) at <https://hackerone.com/gsa_bbp/> for a potential bounty.
34+
35+
## Supported Versions
36+
37+
Please note that only certain branches are supported with security updates.
38+
39+
| Version (Branch) | Supported |
40+
| ---------------- | ------------------ |
41+
| main | :white_check_mark: |
42+
| other | :x: |
43+
44+
When using this code or reporting vulnerabilities please only use supported
45+
versions.

0 commit comments

Comments
 (0)