docs: add security disclosure policy#1117
Conversation
|
|
I have read the CLA Document and I hereby sign the CLA You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot. |
@emdash-cms/admin
@emdash-cms/auth
@emdash-cms/blocks
@emdash-cms/cloudflare
emdash
create-emdash
@emdash-cms/gutenberg-to-portable-text
@emdash-cms/x402
@emdash-cms/plugin-ai-moderation
@emdash-cms/plugin-atproto
@emdash-cms/plugin-audit-log
@emdash-cms/plugin-color
@emdash-cms/plugin-embeds
@emdash-cms/plugin-forms
@emdash-cms/plugin-webhook-notifier
commit: |
What does this PR do?
Adds a root
SECURITY.mdso researchers have a clear private route for vulnerability reports and existing GitHub security advisories. The policy covers GitHub private vulnerability reporting, EmDash-specific report fields/scope examples, coordinated disclosure, and safe-harbor boundaries without promising bounty terms.Closes #993
Type of change
Checklist
pnpm typecheckpasses — not run; documentation-only changepnpm lintpasses — not run; documentation-only changepnpm testpasses (or targeted tests for my change) — not run; documentation-only changepnpm formathas been run — not run; Markdown-only change,git diff --checkpassedmessages.pochanges except in translation PRs — a workflow extracts catalogs on merge tomain.AI-generated code disclosure
Screenshots / test output
Verification run locally:
No build/test run because this only adds
SECURITY.md.