Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a security policy #1000

Open
Erb3 opened this issue Sep 9, 2024 · 0 comments
Open

Create a security policy #1000

Erb3 opened this issue Sep 9, 2024 · 0 comments

Comments

@Erb3
Copy link

Erb3 commented Sep 9, 2024

Please create a security policy detailing contacting information, as this helps security researchers privately report issues.

The most important step in the process is providing a way for security researchers to contact your organization. The easier it is for them to do so, the more likely it is that you'll receive security reports.

— OWASP Cheatsheet Series on Vulnerability Disclosure

Locations this could be located include but are not limited to:

  • SECURITY.md at the root of the GitHub repository. This has the added benefit of showing up on the "Security" GitHub tab.
  • /.well-known/security.txt on the website. See securitytxt.org.
  • Page on the frontend, linked to in the footer or similar.

The most common methods of communication for open-source software are E-Mail and GitHub private vulnerability reporting. The only mention of security reporting I found, was hidden in a small bubble on the login form. You have to go digging to find this, which is a bit annoying.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant