Skip to content

Commit

Permalink
Add SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
pocke committed Feb 7, 2024
1 parent 1bc9c7f commit e377948
Showing 1 changed file with 15 additions and 0 deletions.
15 changes: 15 additions & 0 deletions docs/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Security Policy of gem_rbs_collection

## Non-security issues

We treat it as an ordinary problem even if `gems/` directory contains malicious code.
Please report them to the issue tracker or open a pull request.

Our test runner (`bin/test`) does not execute any code written in `gems/` directory. `rbs` command and library also do not execute any code from this repository.
So it does not cause any security issue even if `gems/` directory contains malicious code.

But if an attacker can inject malicious code to `bin/test`, `rbs` command or the library, it would be a security issue. Please report the problem with the following steps.

## Reporting a Vulnerability

See https://www.ruby-lang.org/en/security/.

0 comments on commit e377948

Please sign in to comment.