Skip to content

docs(security): add links to SECURITY.md (Scorecard Security-Policy 4->10)#1

Merged
charliie-dev merged 1 commit into
mainfrom
docs/security-policy-links
Jun 14, 2026
Merged

docs(security): add links to SECURITY.md (Scorecard Security-Policy 4->10)#1
charliie-dev merged 1 commit into
mainfrom
docs/security-policy-links

Conversation

@charliie-dev

Copy link
Copy Markdown
Contributor

Scorecard's Security-Policy check scores: present(gate) + links(+6) + text(+3) + disclosure(+1). The org policy currently scores 4 (text+disclosure) and was missing the +6 for links - it contained no URL/email. Adds concrete https references (GitHub PVR guide, coordinated-disclosure docs, org profile) so the check reaches 10 across all repos that inherit this org-level policy. Content otherwise unchanged.

Copilot AI review requested due to automatic review settings June 14, 2026 11:50
@charliie-dev charliie-dev merged commit 4347187 into main Jun 14, 2026
3 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

此 PR 更新組織層級的 SECURITY.md,補上可被外部檢查(如 OpenSSF Scorecard Security-Policy)辨識的具體連結參考,讓繼承此政策的儲存庫能取得更完整的安全政策評分,同時維持原本政策文字的意圖不變。

Changes:

  • 在政策適用範圍與通報流程中加入組織頁面與 GitHub PVR 指引連結
  • 新增「References」章節,集中列出相關安全揭露/通報參考資源

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread SECURITY.md
Comment on lines +60 to +61
- GitHub Private Vulnerability Reporting:
<https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/about-coordinated-disclosure-of-security-vulnerabilities>
Comment thread SECURITY.md
impact assessment.

See GitHub's guide for step-by-step instructions:
<https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants