From 58e032d79a4cedd24e3caf90ccf2f587f5cc19d3 Mon Sep 17 00:00:00 2001 From: mattn Date: Fri, 10 Apr 2026 16:17:13 +0900 Subject: [PATCH] Revise SECURITY.md for version support and reporting Updated security policy to reflect supported versions and reporting guidelines. --- SECURITY.md | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..26d9c8b --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,33 @@ +# Security Policy + +## Supported Versions + +Only the latest release on the `v1.14.x` line receives security fixes. + +| Version | Supported | +| -------- | ------------------ | +| 1.14.x | :white_check_mark: | +| < 1.14 | :x: | + +## Scope + +`go-sqlite3` is a CGo binding that bundles the SQLite amalgamation +(`sqlite3-binding.c` / `sqlite3-binding.h`). Please report issues to the +appropriate project: + +- Bugs in the Go binding layer, CGo glue, build tags, or this repository's + own code: report here. +- Vulnerabilities in SQLite itself: please report them upstream to the + SQLite developers at . Once a fix is released + upstream, this repository will update the bundled amalgamation. + +## Reporting a Vulnerability + +Please **do not** open a public GitHub issue for security problems. + +Use GitHub's private vulnerability reporting: + + +This project is maintained on a best-effort basis by volunteers, so please +allow reasonable time for investigation and a fix before any public +d