Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Security Policy

## Reporting a Vulnerability

Please report any security vulnerabilities by emailing us at [support@datacommons.org](mailto:support@datacommons.org). Please do not open a public issue or pull request.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

It is highly recommended to set expectations for security researchers by including a response timeline (e.g., acknowledging the report within 48 hours). This encourages responsible disclosure and establishes clear communication.

Suggested change
Please report any security vulnerabilities by emailing us at [support@datacommons.org](mailto:support@datacommons.org). Please do not open a public issue or pull request.
Please report any security vulnerabilities by emailing us at [support@datacommons.org](mailto:support@datacommons.org). Please do not open a public issue or pull request. We will acknowledge receipt of your report within 48 hours and keep you updated on the progress of our investigation.


### What to Include in the Report

To help us address the issue as quickly as possible, please include the following details in your report:
- A description of the vulnerability and its potential impact.
- Step-by-step instructions (or a proof-of-concept script) to reproduce the issue.
- Any details about the environment or configuration where the issue was found.

We appreciate your help in keeping Data Commons secure!