Skip to content

docs: add security policy#24

Merged
JRemitz merged 1 commit intomainfrom
docs/security-policy
Apr 10, 2026
Merged

docs: add security policy#24
JRemitz merged 1 commit intomainfrom
docs/security-policy

Conversation

@JRemitz
Copy link
Copy Markdown
Contributor

@JRemitz JRemitz commented Apr 10, 2026

Summary

Adds SECURITY.md so GitHub renders a policy in the Security tab and checks off "Security policy" in Community Standards. Documents scope (in-scope: credential leakage, command injection, plugin loader, path traversal; out-of-scope: individual plugins and upstream APIs), directs reporters to GitHub's private vulnerability reporting with git-security@email.remitz.us as a fallback, and notes best-effort SLAs for a small-team project.

Follow-up

  • Enable Private Vulnerability Reporting under Settings → Code security, otherwise the "Report a vulnerability" button referenced in the policy won't appear in the Security tab.

Documents supported versions, scope, and private vulnerability reporting
channel so GitHub surfaces a policy in the Security tab and Community
Standards checklist.
@JRemitz JRemitz merged commit 7ce86e8 into main Apr 10, 2026
8 checks passed
@JRemitz JRemitz deleted the docs/security-policy branch April 10, 2026 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant