diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..c3027f1 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,22 @@ +# Security Policy + +## Supported Versions + +Our only supported version is the current version that the bot/code is on; **all** other versions are currently unsupported! + +## Reporting a Vulnerability + +So... You have discovered a vulnerability within our code. What's next? + +Next up is you have to make a report in the security tab, so that the development team can investigate your report. Reports are acknowledged within 72 hours, and a fix is output within a week (7 days) after acknowledgment IF the security vulnerability is true! +We (TheCodeVerseHub) ask you to make sure to report true security vulnerabilities because they **NEED** to get fixed right away! + +## Acknowledgment of the reported security vulnerability + +We do acknowledge reports within 72 hours and start investigating after alerting the rest of the team about your reported security vulnerability. + +## What will we do if the report is true? + +We will send back a message alerting the member that the report is true and is working on a fix right away. After a patch is sent out, we will update you and the Discord server about the security vulnerability that was patched. + +## We (TheCodeVerseHub) thank you in advance for reporting ANY security vulnerabilities that you do find within our code before they can be exploited!