Skip to content

Conversation

joycebrum
Copy link
Contributor

Changes

Closes #221

  • Create the security.md file with a standard body

It needs yet a security email to gather possible vulnerabilities reports.

I've proposed this vulnerability disclosure timeline but let me know if you are more confortable with a different one.

PS: the Security Advisory is a github tool to Vulnerabilities Disclosures (I've seen you've already familiar with it).

Besides that feel free to edit or suggest any changes to this document, it is supposed to reflect the amount of effort the team can offer to handle vulnerabilities.

@joycebrum
Copy link
Contributor Author

Another option is to use the github advisories to receive vulnerabilities reports, if you rather I can update the doc to mention it instead of emailing. But it need to be enabled and it is in beta yet.

https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Create a Security Policy
2 participants