all: add Security Policy (SECURITY.md)

This should help direct reports to the correct channel.

Change-Id: I468fc5ecaf81d9c8b95765f1fd7de9c5b5adaf2e
Reviewed-on: https://go-review.googlesource.com/c/protobuf/+/553576
Reviewed-by: Christian Höppner <hoeppi@google.com>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
This commit is contained in:
Michael Stapelberg 2024-01-03 13:54:02 +01:00
parent 9f73929456
commit 56dad288dc

4
SECURITY.md Normal file
View File

@ -0,0 +1,4 @@
To report a security issue, please use [https://g.co/vulnz](https://g.co/vulnz).
We use g.co/vulnz for our intake, and do coordination and disclosure here on
GitHub (including using GitHub Security Advisory). The Google Security Team will
respond within 5 working days of your report on g.co/vulnz.