Skip to content

Initial SECURITY.md file#777

Open
sabrina-ngrok wants to merge 1 commit intomainfrom
sabrina/create-security-file
Open

Initial SECURITY.md file#777
sabrina-ngrok wants to merge 1 commit intomainfrom
sabrina/create-security-file

Conversation

@sabrina-ngrok
Copy link
Contributor

@sabrina-ngrok sabrina-ngrok commented Mar 12, 2026

What

Create SECURITY.md file

Generated view: https://github.com/ngrok/ngrok-operator/blob/926bfa531945ae4a34b7f7a39832ccfc7c78b2ca/SECURITY.md

How

Claude generated using example files

Breaking Changes

Are there any breaking changes in this PR?

@sabrina-ngrok sabrina-ngrok requested a review from a team as a code owner March 12, 2026 14:53
@github-actions github-actions bot added the size/M Denotes a PR that changes 30-99 lines label Mar 12, 2026

### Out of Scope

- Vulnerabilities in the ngrok platform or ngrok agent itself — please report those via [ngrok's security disclosure process](https://ngrok.com/security)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i actually don't see a way to submit a report on this page. this might be something to check with @awillett31

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

these also get reported to security@ngrok.com

Copy link
Collaborator

@alex-bezek alex-bezek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

seems pretty good to me. might get eyes from security on it to see what theyt hink

@awillett31
Copy link

Is there any other type of testing we don't want folks doing on the operator? We can always update this later, too, if we start getting reports that should be out of scope.

Otherwise, looks good to me!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/M Denotes a PR that changes 30-99 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants