Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create Security Policy #3692

Open
wants to merge 3 commits into
base: main
Choose a base branch
from
Open

Create Security Policy #3692

wants to merge 3 commits into from

Conversation

diogoteles08
Copy link

Closes #3691

I've created the SECURITY.md file following a GitHub's template and considering that you'd request that users report vulnerabilities through the security advisory, which is a handy new GitHub feature, but it's still in beta and has to be manually enabled by a maintainer.

If you're interested in this feature, you can activate it following this steps:

  1. Click on this link to go to Code security & analysis section on your repo's settings
  2. Click "Enable" for "Private vulnerability reporting (Beta)"

However, if you'd rather not use this feature, you can also request users to report vulnerabilities to an email. If that's the case, let me know which email you would like to receive the reports and I can submit the change.

Additionally, feel free to edit or suggest any changes to this document, it is supposed to reflect the amount of effort the team can offer to handle vulnerabilities.

@Fil Fil mentioned this pull request Sep 14, 2023
@diogoteles08
Copy link
Author

Hey! This issue/PR has been idle for quite some time. Do you plan on considering these changes? If not, I'll probably wait up to 2 more months and close the issue.

Thanks!

@diogoteles08
Copy link
Author

Hey! I realized it actually doesn't make much sense to close without any position from the maintainers, as it can become of your interest on the future =)

I just updated the branch with latest main changes, let me know if there is anything else I can do to help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

Add a Security-Policy
1 participant