summaryrefslogtreecommitdiffhomepage
path: root/SECURITY.md
blob: 2b48e47e3ae662cc50755b78c91e1adfab808b25 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
# Security Policy

## Latest Versions

We advise users to run the most recent mainline or stable release of nginx.

## Reporting a Vulnerability

Please report any vulnerabilities via one of the following methods
(in order of preference):

1. [Report a vulnerability](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability)
within this repository. We are using the Github workflow that allows us to
manage vulnerabilities in a private manner and to interact with reporters
securely.

2. [Report directly to F5](https://www.f5.com/services/support/report-a-vulnerability).

3. Report via email to security-alert@nginx.org.
This method will be deprecated in the future.