-
Notifications
You must be signed in to change notification settings - Fork 56
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Desired Behavior
Need to leverage GitHub scanning / dependabot v2.
Need to have a SECURITY.md file so that contributors are aware of all KNOWN KNOWNS and KNOWN UNKNOWNS.
At a minimum:
- Security Policy
- Security Advisories
- Dependabot Alerts
- Code Scanning
Benefits
- Users will have a report of clear list of actions taken on security reports issued by agencies AND
- Contributors have a clear process on how to take action on vulnerability alerts.
- Both Users and Contributors can TRUST the software to be as free as possible from known vulnerabilities
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request
