Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SECURITY.md with vulnerability reporting and disclosure policy #274

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

iAnonymous3000
Copy link
Contributor

This introduces a SECURITY.md file to the project, outlining the OWASP dep-scan security policy. The file covers the following key points:

  • Supported versions and commitment to providing security updates
  • Instructions for reporting vulnerabilities to the project maintainer
  • Overview of the vulnerability management process
  • Statement on the current absence of a bug bounty program
  • Secure development practices followed by the project
  • Placeholder for acknowledging responsible vulnerability disclosures

The main contact for reporting vulnerabilities is listed as prabhu@appthreat.com.

This policy demonstrates the project's commitment to maintaining a secure codebase and handling vulnerability reports responsibly. It provides guidance to security researchers and users on how to engage with the project for security-related concerns.

Please feel free to modify it in any way that you believe is suitable.

This introduces a SECURITY.md file to the project, outlining the OWASP dep-scan security policy. The file covers the following key points:
- Supported versions and commitment to providing security updates
- Instructions for reporting vulnerabilities to the project maintainer
- Overview of the vulnerability management process
- Statement on the current absence of a bug bounty program
- Secure development practices followed by the project
- Placeholder for acknowledging responsible vulnerability disclosures

The main contact for reporting vulnerabilities is listed as
prabhu@appthreat.com.

This policy demonstrates the project's commitment to maintaining a secure codebase and handling vulnerability reports responsibly. It provides guidance to security researchers and users on how to engage with the project for security-related concerns.

Please feel free to modify it in any way that you believe is suitable.

Signed-off-by: Sooraj Sathyanarayanan <32236127+iAnonymous3000@users.noreply.github.com>
@prabhu
Copy link
Member

prabhu commented Mar 14, 2024

@iAnonymous3000 Thank you for this contribution! I think the content needs some changes. Will do it later.

At the moment, we treat security issues as any other issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants