Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Security Enhancement: Add a Security Policy #365

Closed
diogoteles08 opened this issue Apr 20, 2023 · 0 comments · Fixed by #366
Closed

Security Enhancement: Add a Security Policy #365

diogoteles08 opened this issue Apr 20, 2023 · 0 comments · Fixed by #366

Comments

@diogoteles08
Copy link
Contributor

Hi! I'm Diogo and I'm back (see #357) hoping to offer a bit more help with security enhancements.

This time I'm here to suggest that you expose a way that users can report eventual vulnerabilities in a safe and efficient way. This is usually done through a Security Policy, which is a GitHub standard document (SECURITY.md) added on the root of the repo and will be visible to the users in the "Security Tab".

image

It is a recommendation from Github itself, and from Scorecard (being a security measure of medium priority).

Aiming to make this change easier, I'll take the liberty of submitting one suggestion of a Security Policy as a PR. Please feel free to edit it directly or ask me for editions until it is in compliance with how godbus/dbus would best handle vulnerability reports.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant