xref: /third_party/libuv/SECURITY.md (revision e66f31c5)
1e66f31c5Sopenharmony_ci# Security Policy
2e66f31c5Sopenharmony_ci
3e66f31c5Sopenharmony_ci## Supported Versions
4e66f31c5Sopenharmony_ci
5e66f31c5Sopenharmony_ciCurrently, we are providing security updates for the latest release in the v1.x series:
6e66f31c5Sopenharmony_ci
7e66f31c5Sopenharmony_ci| Version | Supported          |
8e66f31c5Sopenharmony_ci| ------- | ------------------ |
9e66f31c5Sopenharmony_ci| Latest v1.x  | :white_check_mark: |
10e66f31c5Sopenharmony_ci
11e66f31c5Sopenharmony_ci## Reporting a Vulnerability
12e66f31c5Sopenharmony_ci
13e66f31c5Sopenharmony_ciIf you believe you have found a security vulnerability in `libuv`, please use the [GitHub's private vulnerability reporting feature](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability) in the [libuv repository](https://github.com/libuv/libuv) to report it to us.
14e66f31c5Sopenharmony_ci
15e66f31c5Sopenharmony_ciThis will allow us to assess the risk, and make a fix available before we add a bug report to the GitHub repository.
16e66f31c5Sopenharmony_ci
17e66f31c5Sopenharmony_ciPlease do:
18e66f31c5Sopenharmony_ci
19e66f31c5Sopenharmony_ci* Provide as much information as you can about the vulnerability.
20e66f31c5Sopenharmony_ci* Provide details about your configuration and environment, if applicable.
21e66f31c5Sopenharmony_ci
22e66f31c5Sopenharmony_ciPlease do not:
23e66f31c5Sopenharmony_ci
24e66f31c5Sopenharmony_ci* Post any information about the vulnerability in public places.
25e66f31c5Sopenharmony_ci* Attempt to exploit the vulnerability yourself.
26e66f31c5Sopenharmony_ci
27e66f31c5Sopenharmony_ciWe take all security bugs seriously. Thank you for improving the security of `libuv`. We appreciate your efforts and responsible disclosure and will make every effort to acknowledge your contributions.