-
Notifications
You must be signed in to change notification settings - Fork 38
docs: Create SECURITY.md with responsible disclosure policy #212
Copy link
Copy link
Closed
Labels
GrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignCampaign: Official CampaignCampaign: Official CampaigndocumentationImprovements or additions to documentationImprovements or additions to documentationgood first issueGood for newcomersGood for newcomerssecuritySecurity related issuesSecurity related issues
Metadata
Metadata
Assignees
Labels
GrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignCampaign: Official CampaignCampaign: Official CampaigndocumentationImprovements or additions to documentationImprovements or additions to documentationgood first issueGood for newcomersGood for newcomerssecuritySecurity related issuesSecurity related issues
Type
Fields
Give feedbackNo fields configured for issues without a type.
Problem Statement
No security policy or responsible disclosure process exists. Security researchers have no documented way to report vulnerabilities.
Evidence
SECURITY.mddoes not exist.Impact
Vulnerabilities may be disclosed publicly instead of privately. No defined response SLA. Potential security issues may go unreported.
Proposed Solution
Create SECURITY.md with:
Acceptance Criteria
File Map
SECURITY.md— newLabels: documentation, security, good first issue
Priority: Medium | Difficulty: Beginner | Estimated Effort: 0.5h
Labels: documentation,security,good first issue
Priority: Medium | Difficulty: Beginner | Estimated Effort: 0.5h
Backlog ID: REPO-029