Skip to content

docs(security): coordinated-disclosure process + realistic reporting policy - #550

Merged
DeusData merged 1 commit into
mainfrom
docs/security-process
Jun 22, 2026
Merged

docs(security): coordinated-disclosure process + realistic reporting policy#550
DeusData merged 1 commit into
mainfrom
docs/security-process

Conversation

@DeusData

Copy link
Copy Markdown
Owner

Adds a public coordinated-disclosure process and refreshes the reporting policy.

  • New `docs/SECURITY-DISCLOSURE.md` — reporter-facing handling process (private fix → cross-platform CI validation → reporter verification → patched release → GitHub Security Advisory + CVE + credit).
  • SECURITY.md — GitHub private vulnerability reporting as the preferred channel (email as fallback), honest best-effort timelines for a solo-maintained project (ack ≤7d / triage ≤14d / fix ≤90d, expedited for high severity) replacing the over-tight 48h/7-day promise, a safe-harbor statement, a request for the reporter’s GitHub handle + email so they can be invited to verify the fix, and a refreshed supported-versions table.

Docs-only; no code changes.

…policy

Add docs/SECURITY-DISCLOSURE.md describing how vulnerability reports are
handled end to end (private fix, cross-platform validation, reporter
verification, patched release, then a GitHub Security Advisory with a CVE
and credit).

Update SECURITY.md: add GitHub private vulnerability reporting as the
preferred channel, replace the over-tight 48h/7-day commitment with honest
best-effort targets for a solo-maintained project, add a safe-harbor
statement, and refresh the stale supported-versions table (0.5.x -> 0.8.x).

Signed-off-by: Martin Vogel <martin.vogel@datadice.io>
@DeusData
DeusData merged commit 53ebeb4 into main Jun 22, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant