Skip to content

docs: Add SECURITY.md #226

Description

@N-thnI

[Docs] Add SECURITY.md

Summary

Add a SECURITY.md documenting how to responsibly report vulnerabilities in this project.

Why this matters

The repo has shipped multiple recent CVE/CodeQL fixes (middleware auth-bypass, sanitizer hardening) but has no disclosure policy. For a project whose whole value proposition is security tooling, a visible reporting process is table stakes and a credibility signal for reviewers.

Acceptance criteria

  • SECURITY.md added at repo root
  • Includes reporting contact/channel
  • States expected response time and disclosure process
  • States supported versions/scope

Technical context

Reference recent security fix commits for context on the kind of issues that should route through this process (e.g. sanitizer fixes, CVE patch to next).

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardThird CampaignCampaign: Third CampaigndocumentationImprovements or additions to documentationgood first issueGood for newcomers

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions