Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Security Policy #134

Open
gabibguti opened this issue Apr 4, 2023 · 4 comments
Open

Add Security Policy #134

gabibguti opened this issue Apr 4, 2023 · 4 comments
Assignees

Comments

@gabibguti
Copy link

Adding a Security Policy is important as it provides guidance on how to report potential vulnerabilities and inform the vulnerabilities disclosure window for this repo.

I recently recommended #132 and, like that change, this one also security-related.

If you agree, I can open a PR to suggest a Security Policy, and we can work together to communicate how the repo can best handle vulnerability reports.

Additional Context

Hi again! I'm Gabriela and I work on behalf of Google and the OpenSSF suggesting supply-chain security changes :)

@r-hang
Copy link

r-hang commented Apr 5, 2023

Hey @gabibguti do you have some examples of what a security policy might look like? We're interested in learning more!

@sywhang sywhang self-assigned this Apr 5, 2023
@gabibguti
Copy link
Author

Hi! Friendly ping here. Are you still planning on working on this change? Otherwise we can close as not planned for now :)

@sywhang
Copy link
Contributor

sywhang commented Aug 23, 2023

Thanks @gabibguti for the ping. There is an ongoing security policy that's pending some review. We'll leave this issue open as we'll be putting the security policy in place for all repos.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants