Skip to content

docs: add private security disclosure policy#264

Open
21pounder wants to merge 1 commit intokerberos-io:masterfrom
21pounder:fix/issue-256-security-disclosure
Open

docs: add private security disclosure policy#264
21pounder wants to merge 1 commit intokerberos-io:masterfrom
21pounder:fix/issue-256-security-disclosure

Conversation

@21pounder
Copy link
Copy Markdown

Add SECURITY.md to define private vulnerability disclosure channels and response expectations.

Also surface security-reporting guidance in:

  • README.md
  • machinery/README.md

Closes #256

Add SECURITY.md and surface reporting guidance in README files.

Refs kerberos-io#256
@cedricve
Copy link
Copy Markdown
Member

Thanks @21pounder makes a lot of sense!

Copy link
Copy Markdown
Contributor

@KilianBoute KilianBoute left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you, does indeed make sense. Approved to merge from me once we have set up the alternative channels to correctly report security issues.

@cedricve
Copy link
Copy Markdown
Member

@21pounder any additional comments? We would also create a separate slack channel #security, which receives notifications on creation.

@21pounder
Copy link
Copy Markdown
Author

Thanks! No additional comments from my side.
Happy to update SECURITY.md once the #security channel is live.
@cedricve, could you approve the PR when ready?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Inquiry regarding recent email communication / Attempting to reach maintainers

3 participants