diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000000..0ee977f87b --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,9 @@ +# Reporting security issues + +The Moby maintainers take security seriously. If you discover a security issue, please bring it to their attention right away! + +### Reporting a Vulnerability + +Please **DO NOT** file a public issue, instead send your report privately to security@docker.com. + +Security reports are greatly appreciated and we will publicly thank you for it. We also like to send gifts—if you're into schwag, make sure to let us know. We currently do not offer a paid security bounty program, but are not ruling it out in the future.