Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a security policy #226

Open
joycebrum opened this issue Sep 12, 2023 · 1 comment · May be fixed by #227
Open

Create a security policy #226

joycebrum opened this issue Sep 12, 2023 · 1 comment · May be fixed by #227

Comments

@joycebrum
Copy link

Hi, I'd like to suggest to create a Security Policy for decimal.js project. It is a GitHub standard document (SECURITY.md) that can be found in the "Security Tab" to instruct users how to report vulnerabilities in a safe and efficient way.

It is a Scorecard Recommendation (being a security measure of medium priority) and a Github Recommendation.

Together with this issue I'll submit one suggestion of Security Policy, feel free to edit it directly or ask me for editions until it is in compliance with how you would best handle vulnerability reports.

Disclosure: I'm from Google (the Google Open Source Security Team) and I'm working on contributing to many open source projects to increase their supply-chain security

@joycebrum joycebrum linked a pull request Sep 12, 2023 that will close this issue
@MikeMcl
Copy link
Owner

MikeMcl commented Sep 13, 2023

Okay, thanks Joyce. I will look at this next week.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants