Browse Source

Create s Security Policy (#4671)

* Create SECURITY.md

* Update test_files.py to include SECURITY.md file

* Update MANIFEST.in to include SECURITY.md file
pull/4691/head
Joyce 2 years ago committed by GitHub
parent
commit
6e6bcca5b2
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
  1. 2
      MANIFEST.in
  2. 13
      SECURITY.md
  3. 1
      tests/extra_python_package/test_files.py

2
MANIFEST.in

@ -3,4 +3,4 @@ recursive-include pybind11/include/pybind11 *.h
recursive-include pybind11 *.py recursive-include pybind11 *.py
recursive-include pybind11 py.typed recursive-include pybind11 py.typed
include pybind11/share/cmake/pybind11/*.cmake include pybind11/share/cmake/pybind11/*.cmake
include LICENSE README.rst pyproject.toml setup.py setup.cfg include LICENSE README.rst SECURITY.md pyproject.toml setup.py setup.cfg

13
SECURITY.md

@ -0,0 +1,13 @@
# Security Policy
## Supported Versions
Security updates are applied only to the latest release.
## Reporting a Vulnerability
If you have discovered a security vulnerability in this project, please report it privately. **Do not disclose it as a public issue.** This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.
Please disclose it at [security advisory](https://github.com/pybind/pybind11/security/advisories/new).
This project is maintained by a team of volunteers on a reasonable-effort basis. As such, please give us at least 90 days to work on a fix before public exposure.

1
tests/extra_python_package/test_files.py

@ -111,6 +111,7 @@ sdist_files = {
"MANIFEST.in", "MANIFEST.in",
"README.rst", "README.rst",
"PKG-INFO", "PKG-INFO",
"SECURITY.md",
} }
local_sdist_files = { local_sdist_files = {

Loading…
Cancel
Save