Skip to content

Commit

Permalink
Create SECURITY.md (#452)
Browse files Browse the repository at this point in the history
* Create SECURITY.md

* Update supported versions section
  • Loading branch information
artemgavrilov committed Apr 19, 2024
1 parent dce1913 commit c2923b4
Showing 1 changed file with 24 additions and 0 deletions.
24 changes: 24 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Security Policy

## Supported Versions

pg_stat_monitor project follows rolling release strategy. So all security updates go to new versions.

## Reporting a Vulnerability

Please report any vulnerabilities to our project in [Jira](https://perconadev.atlassian.net/jira/software/c/projects/PG/issues).

If the vulnerability is accepted and confirmed by our experts, you should normally expect us to deliver
a version with a fix according to the timelines provided below:

For Percona created software (our engineers wrote the code):

- Low/Medium: 120 days
- High: 90 days
- Critical: ASAP but should not exceed 30 days

For Non-Percona created software (upstream provided/packaged) from the time the vendor releases a patch:

- Low/Medium: 2nd release from current version
- High: Next release
- Critical: Hotfix or no later than next release (our regular release cadence is once every month)

0 comments on commit c2923b4

Please sign in to comment.