Skip to content

Conversation

@misrasaurabh1
Copy link
Contributor

@misrasaurabh1 misrasaurabh1 commented Aug 7, 2025

PR Type

Documentation


Description

  • Add SECURITY.md outlining vulnerability policy

  • Define supported versions commitment

  • Specify vulnerability reporting channels

  • Describe acknowledgment and advisory process


File Walkthrough

Relevant files
Documentation
SECURITY.md
Add security vulnerability disclosure policy                         

SECURITY.md

  • Created new SECURITY.md file
  • Outlines supported versions policy
  • Provides reporting procedures and contacts
  • Details acknowledgment and advisory process
+19/-0   

@misrasaurabh1 misrasaurabh1 merged commit 9e12e94 into main Aug 7, 2025
18 of 19 checks passed
@github-actions
Copy link

github-actions bot commented Aug 7, 2025

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Version Support Clarity

The policy commits to fixing security issues only for the latest client version without specifying which past versions are supported or for how long. Clarify the supported versions and maintenance window for security fixes.

Since Codeflash is moving quickly, we can only commit to fixing security issues for the latest version of codeflash client.
If a vulnerability is discovered in our backend, we will release the fix for all the users.
Response Timeframes

The document states acknowledgements will be immediate and fixes “as soon as we can” but lacks clear SLAs or timelines for response and remediation. Consider defining specific acknowledgement and resolution timeframes.

We commit to acknowledging vulnerability reports immediately, and will work to fix active vulnerabilities as soon as we can. We will publish resolved vulnerabilities in the form of security advisories on our GitHub security page. Critical incidents will be communicated both on the GitHub security page and via email to all affected users.

@github-actions
Copy link

github-actions bot commented Aug 7, 2025

PR Code Suggestions ✨

No code suggestions found for the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant