diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..96c5025 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,33 @@ +# Security Policy + +## Supported Versions + +ESP-MQTT is distributed as an [ESP-IDF component](https://components.espressif.com/components/espressif/mqtt/versions/1.1.0/readme) and through the ESP-IDF Component Registry. + +When ESP-MQTT is used as part of ESP-IDF, please refer to the [ESP-IDF Support Period Policy](https://github.com/espressif/esp-idf/blob/master/SUPPORT_POLICY.md) +for information about supported ESP-IDF versions. + +For the managed ESP-MQTT component, users are encouraged to use the latest available release. + +## Reporting a Vulnerability + +Please follow the [Espressif Security Incident Response Process](https://www.espressif.com/en/support/documents/advisories) to +report a suspected security vulnerability. + +Please **do not create a public GitHub issue, discussion, or pull request** for a security vulnerability. + +When reporting an issue related to ESP-MQTT, please provide as much +relevant information as possible, including: + +- The affected ESP-MQTT version or commit +- The ESP-IDF version, if applicable +- The affected SoC or target +- A description of the vulnerability and its potential security impact +- Configuration required to reproduce the issue +- Steps to reproduce the issue +- A proof of concept, logs, or other supporting information, if + available + +If you are unsure whether an issue has security implications, please +report it through the security reporting process rather than disclosing +it publicly.