Skip to content

Commit 166c2e1

Browse files
Create SECURITY.md
1 parent c41409b commit 166c2e1

File tree

1 file changed

+28
-0
lines changed

1 file changed

+28
-0
lines changed

SECURITY.md

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
# Mergington High School Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
At Mergington High, we take the security of our Extra-Curricular Activities website seriously, especially
6+
since it contains student information. If you discover a security vulnerability, please follow these steps:
7+
8+
1. **Do not** create an issue on this repository, disclose the vulnerability publicly, or discuss it with other teachers/students.
9+
1. In the top navigation of this repository, click the **Security** tab.
10+
1. In the top right, click the **Report a vulnerability** button.
11+
1. Fill out the provided form. It will request information like:
12+
- A description of the vulnerability
13+
- Steps to reproduce the issue
14+
- Potential impact on student data or website functionality
15+
- Suggested fix (if you have one)
16+
1. Email the IT Club faculty advisor at [email protected] and inform them you have made a report. **Do not** include any vulnerability details.
17+
18+
## Response Timeline
19+
20+
- We will acknowledge receipt of your report within 2 school days
21+
- We will provide an initial assessment within 5 school days
22+
- Critical issues affecting student data will be addressed immediately
23+
- We will create a private fork to solve the issue and invite you as a collaborator so you can see our progress and contribute.
24+
25+
## Thank You
26+
27+
Your help in keeping our school's digital resources secure is greatly appreciated!
28+
Responsible disclosure of security vulnerabilities helps protect our entire school community.

0 commit comments

Comments
 (0)