From 3d393d8e545914809753896f96691c903f86069a Mon Sep 17 00:00:00 2001 From: Jonathan Dumont <5204724+JOduMonT@users.noreply.github.com> Date: Sat, 3 Oct 2026 08:50:50 -0400 Subject: [PATCH] Write a repo-specific SECURITY.md --- SECURITY.md | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 7d90564..5e088f5 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -4,18 +4,21 @@ Deployment config for a shared PostgreSQL instance pinned to a stable Alpine tag ## Supported versions -Only the current `main` branch is supported. Fixes land on `main`; there are no release branches. +Only the current `main` branch is supported. +Fixes land on `main`; there are no release branches. ## Reporting a vulnerability -Please report privately. Do not open a public issue or pull request. +Please report privately. +Do not open a public issue or pull request. - **Preferred:** [report a vulnerability](https://github.com/JOduMonT/postgresql/security/advisories/new) through GitHub private vulnerability reporting. - **Email:** jodumont+security@gmail.com - Include what you found, the affected file or service, steps to reproduce and the impact you see. - Do not access, change or delete data that is not yours, and do not run denial-of-service or automated scanning against live systems. -You can expect an acknowledgement within 3 business days and a status update within 10. Confirmed issues are fixed as quickly as severity allows, and you are credited in the fix unless you prefer not to be. +You can expect an acknowledgement within 3 business days and a status update within 10. +Confirmed issues are fixed as quickly as severity allows, and you are credited in the fix unless you prefer not to be. ## Scope @@ -30,8 +33,10 @@ Out of scope: ## How this repository is kept safe -- Dependabot alerts and security updates are on; a vulnerable dependency gets an automatic pull request. Routine version bumps are opened by Renovate, and `.github/dependabot.yml` keeps Dependabot's own version updates off to avoid duplicate pull requests. -- Dependabot pull requests are merged automatically by `.github/workflows/dependabot-auto-merge.yml` once every other check passes. Major version bumps are left open for review. +- Dependabot alerts and security updates are on; a vulnerable dependency gets an automatic pull request. + Routine version bumps are opened by Renovate, and `.github/dependabot.yml` keeps Dependabot's own version updates off to avoid duplicate pull requests. +- Dependabot pull requests are merged automatically by `.github/workflows/dependabot-auto-merge.yml` once every other check passes. + Major version bumps are left open for review. - GitHub secret scanning with push protection and CodeQL code scanning are enabled. - Credentials are injected by Coolify or `.env`, never committed; keep the instance internal-only. - Image bumps come from Renovate and are smoke-tested in CI; a major upgrade is a dump and restore, done by hand.