diff --git a/README.md b/README.md index faac9f1f8..7a4e5ead9 100644 --- a/README.md +++ b/README.md @@ -13,7 +13,7 @@ The application comes with a **developer friendly comprehensive guidebook** whic 1. Instructions for setting up DVNA 2. Instructions on exploiting the vulnerabilities 3. Vulnerable code snippets and instructions on fixing vulnerabilities -4. Recommendations for avoid such vulnerabilities +4. Recommendations for avoid such vulnerabilitiess 5. References for learning more The blog post for this release is at https://blog.appsecco.com/damn-vulnerable-nodejs-application-dvna-by-appsecco-7d782d36dc1e diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..034e84803 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ +# Security Policy + +## Supported Versions + +Use this section to tell people about which versions of your project are +currently being supported with security updates. + +| Version | Supported | +| ------- | ------------------ | +| 5.1.x | :white_check_mark: | +| 5.0.x | :x: | +| 4.0.x | :white_check_mark: | +| < 4.0 | :x: | + +## Reporting a Vulnerability + +Use this section to tell people how to report a vulnerability. + +Tell them where to go, how often they can expect to get an update on a +reported vulnerability, what to expect if the vulnerability is accepted or +declined, etc.